Chunghwa Telecom TenderDocTransfer是中国中华电信(Chunghwa Telecom)公司的一款应用程序。 Chunghwa Telecom TenderDocTransfer 0.41.151版本到0.41.156版本存在跨站脚本漏洞,该漏洞源于容易受到反射型跨站脚本攻击和缺少CSRF保护,可能导致未认证的远程攻击者通过网络钓鱼执行任意JavaScript代码,并利用Node.Js特性运行OS命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Chunghwa Telecom | TenderDocTransfer | 0.41.151 ~ 0.41.156 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/Jimmy01240397/CVE-2024-12641_12642_12645 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2024-12643 | 8.1 HIGH | Chunghwa Telecom tbm-client - Arbitrary File Delete |
| CVE-2024-12646 | 8.1 HIGH | Chunghwa Telecom topm-client - Arbitrary File Delete |
| CVE-2024-12642 | 8.1 HIGH | Chunghwa Telecom TenderDocTransfer - Arbitrary File Write |
| CVE-2024-12644 | 7.1 HIGH | Chunghwa Telecom tbm-client - Arbitrary File Copy and Paste |
| CVE-2024-12645 | 6.5 MEDIUM | Chunghwa Telecom topm-client - Arbitrary File Read |
No comments yet