Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.
Solution:
The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-10321-3cae5-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-10325-70192-2.html | third party advisory |