References https://www.twcert.org.tw/tw/cp-132-7033-878ab-1.html https://tp2rc.tanet.edu.tw/node/670 https://www.twcert.org.tw/newepaper/cp-151-7033-878ab-3.html https://github.com/advisories/GHSA-6f3w-c86g-f4j3 https://www.cve.org/CVERecord?id=CVE-2023-24836 https://avd.aliyun.com/detail?id=AVD-2023-24836 https://oits.pu.edu.tw/p/406-1002-41396,r11.php?Lang=zh-tw https://net.nthu.edu.tw/netsys/mailing:announcement:20230411_01?do=export_pdf
Related VulnerabilitiesPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-44177: Kirby CMS 5.3.0-5.4.0 - Path TraversalPoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2026-54917: SeaweedFS <= 4.29 - Path Traversal File WritePoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCnodogsplash-lfi: Nodogsplash - Directory TraversalPoCCVE-2025-71324: Flowise - Path TraversalPoCCVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)PoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path TraversalPoCCVE-2024-56511: DataEase < 2.10.4 - Authentication Bypass via Whitelist Path TraversalPoCCVE-2025-71334: Flowise - Path TraversalPoCCVE-2026-31831: Tautulli <= 2.16.1 - Path Traversal