{"api_version":"1","generated_at":"2026-07-23T23:41:52+00:00","cve":"CVE-2023-37289","urls":{"html":"https://cve.report/CVE-2023-37289","api":"https://cve.report/api/cve/CVE-2023-37289.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-37289","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-37289"},"summary":{"title":"CVE-2023-37289","description":"It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in  InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. This issue affects Document On-line Submission and Approval System: 22547, 22567.","state":"PUBLIC","assigner":"cve@cert.org.tw","published_at":"2023-07-20 03:15:00","updated_at":"2023-07-28 15:35:00"},"problem_types":["CWE-434"],"metrics":[],"references":[{"url":"https://www.twcert.org.tw/tw/cp-132-7225-cef32-1.html","name":"https://www.twcert.org.tw/tw/cp-132-7225-cef32-1.html","refsource":"MISC","tags":[],"title":"TWCERT/CC台灣電腦網路危機處理暨協調中心|企業資安通報協處|資安情資分享|漏洞通報|資安聯盟|資安電子報-英福達科技 電子公文系統 - Arbitrary File Upload","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-37289","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37289","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"37289","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"infodoc","cpe5":"document_on-line_submission_and_approval_system","cpe6":"22547","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"37289","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"infodoc","cpe5":"document_on-line_submission_and_approval_system","cpe6":"22567","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-37289","ASSIGNER":"cve@cert.org.tw","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"It is identified a vulnerability of Unrestricted Upload of File with Dangerous Type in the file uploading function in  InfoDoc Document On-line Submission and Approval System, which allows an unauthenticated remote attacker can exploit this vulnerability without logging system to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service. This issue affects Document On-line Submission and Approval System: 22547, 22567."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-434 Unrestricted Upload of File with Dangerous Type","cweId":"CWE-434"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"InfoDoc","product":{"product_data":[{"product_name":"Document On-line Submission and Approval System","version":{"version_data":[{"version_affected":"=","version_value":"22547"},{"version_affected":"=","version_value":"22567"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.twcert.org.tw/tw/cp-132-7225-cef32-1.html","refsource":"MISC","name":"https://www.twcert.org.tw/tw/cp-132-7225-cef32-1.html"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"advisory":"TVN-202307007","discovery":"EXTERNAL"},"solution":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Contact support from InfoDoc"}],"value":"Contact support from InfoDoc"}],"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-07-20 03:15:00","lastModifiedDate":"2023-07-28 15:35:00","problem_types":["CWE-434"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:infodoc:document_on-line_submission_and_approval_system:22567:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:infodoc:document_on-line_submission_and_approval_system:22547:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}