Security Advisory

CVE-2024-25533

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-05-08 00:00:00
Last updated 2024-08-01 23:44:09
Assigner mitre
State PUBLISHED

Description

Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFileUpdate.aspx). This vulnerability can allow attackers to write files to the server or execute arbitrary commands via crafted SQL statements.