Sploit.io - Search

Product: U-Office Force, version: < 28.0

CVE-2025-2395

Severity: CRITICAL

Description: The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.

CVSS Score: 9.8

Affected Products:

  • e-Excellence U-Office Force - Versions: 0

References:

CVE-2025-2396

Severity: HIGH

Description: The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

CVSS Score: 8.8

Affected Products:

  • e-Excellence U-Office Force - Versions: 0

References: