Vulnerability Description
Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Landray | Landray Office Automation | - |
Related Weaknesses (CWE)
References
- https://codeantenna.com/a/DXQfemaZEHExploitThird Party Advisory
- https://developpaper.com/lanling-oa-foreground-arbitrary-file-reading-vulnerabilExploitThird Party Advisory
- https://codeantenna.com/a/DXQfemaZEHExploitThird Party Advisory
- https://developpaper.com/lanling-oa-foreground-arbitrary-file-reading-vulnerabilExploitThird Party Advisory
FAQ
What is CVE-2022-34924?
CVE-2022-34924 is a vulnerability with a CVSS score of 7.5 (HIGH). Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerability via the component /sys/ui/extend/varkind/custom.jsp.
How severe is CVE-2022-34924?
CVE-2022-34924 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-34924?
Check the references section above for vendor advisories and patch information. Affected products include: Landray Landray Office Automation.