Source: Ministry of education information & communication security contingency platform
Publication Number | TACERT-ANA-2024102404101616 | Publication Time | 2024/10/24 16:39 |
Incident Type | ANA-Vulnerability Alert | Discovery Time | 2024/10/21 16:39 |
Impact Level | Medium | ||
[Subject] 【Vulnerability Alert】Multiple Critical Security Vulnerabilities in WellChoose Information Administrative Management System |
|||
[Content] Forwarded from TWCERTCC-200-202410-00000012 On October 21, 2024, TWCERT/CC issued an alert regarding multiple critical security vulnerabilities in the WellChoose Information Administrative Management System: WellChoose Information Administrative Management System - Arbitrary File Upload TVN-202410019, CVE-2024-10201, CVSS: 8.8 The system does not properly validate uploaded file types, allowing remote attackers with general access to upload and execute web shell backdoor programs. WellChoose Information Administrative Management System - OS Command Injection TVN-202410020, CVE-2024-10202, CVSS: 8.8 The system contains an OS Command Injection vulnerability, enabling remote attackers with general access to inject and execute arbitrary OS commands." Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
[Affected Platform] Administrative Management System |
|||
[Recommended Actions] Contact the vendor for patch updates. |
|||
[Reference] ●WellChoose Information Administrative Management System - Arbitrary File Upload https://www.twcert.org.tw/tw/cp-132-8160-756b6-1.html ●WellChoose Information Administrative Management System - OS Command Injection https://www.twcert.org.tw/tw/cp-132-8162-dc491-1.html |