Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
WorkforceROI Xpede 4.1 stores temporary expense claim reports in a world-readable and indexable /reports/temp directory, which allows remote attackers to read the reports by accessing the directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WorkforceROI XPede文件保护不够强壮漏洞
Vulnerability Description
XPede是一款基于WEB的项目审核软件,可运行在Microsoft Windows操作系统下。 XPede在文件权限设置上存在漏洞,可以导致远程攻击者获得其他用户的临时报表内容信息。 当用户提交费用声明时,文件就会把文件存储在全局可读目录'/reports/temp'中,默认这个目录是可索引列表的,远程客户端可以远程访问此目录并访问其他用户报表内容信息。 如果文件索引列表功能被关闭,攻击者仍旧可以获得文件信息。由于安全原因,文件名指定为随机数,不过此随机数生成机制存在问题,只允许长度为5的限制在[0-9
CVSS Information
N/A
Vulnerability Type
N/A