References https://www.twcert.org.tw/tw/cp-132-6360-7bf50-1.html https://www.twcert.org.tw/newepaper/cp-151-6360-7bf50-3.html https://www.cvedetails.com/cve/CVE-2022-35221/ https://nvd.nist.gov/vuln/detail/CVE-2022-35221 https://www.twcert.org.tw/en/cp-139-6362-1c5d8-2.html https://github.com/advisories/GHSA-qp55-wf2p-vrj5 https://www.teamplus.tech/
Related VulnerabilitiesMPDV Mikrolab GmbH HYDRA X, MIP 2, FEDRA 2 /hx/resources/public/$SCHEMAS$ 文件读取漏洞(CVE-2025-12055)微力同步 /rest/f/api/resources/f96956469e7be39d 文件读取漏洞PoC微力同步Verysync resources 任意文件读取漏洞微力同步-VeriSync resources 任意文件读取漏洞HJSoft HCM Human Resources Management System /selfservice/lawresource/downlawbase SQL 注入漏洞(CVE-2025-10197)PoC博硕BGM InvokeWithOutParam SQL注入漏洞PoCCVE-2015-3648: ResourceSpace - Local File inclusionPoCCVE-2021-41951: Resourcespace - Cross-Site ScriptingPoCCVE-2022-1398: External Media without Import <=1.1.2 - Authenticated Blind Server-Side Request ForgeryPoCCVE-2022-31260: ResourceSpace - Metadata ExportPoCCVE-2024-4885: Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal - Remote Code Execution