NA

CVE-2024-25533

Published: 08/05/2024 Updated: 09/05/2024

Vulnerability Summary

Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow malicious users to write files to the server or execute arbitrary commands via crafted SQL statements.