PT-2024-12821 · Dzzoffice · Dzzoffice

Published

2024-01-05

·

Updated

2024-01-11

·

CVE-2023-39853

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dzzoffice version 2.01
Description The issue allows remote attackers to obtain sensitive information via the doobj and doevent parameters in the Network Disk backend module. This is a SQL Injection vulnerability.
Recommendations For Dzzoffice version 2.01, as a temporary workaround, consider restricting access to the Network Disk backend module until a patch is available. Avoid using the doobj and doevent parameters in the affected module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-39853

Affected Products

Dzzoffice