References https://www.twcert.org.tw/tw/cp-132-6830-28746-1.html https://www.ycrc.edu.tw/show_news.php?id=499 https://net.nthu.edu.tw/netsys/mailing:announcement:20230104_04 https://rc161.ndhu.edu.tw/p/406-1185-203790,r11.php?Lang=zh-tw https://ic2.asia.edu.tw/zh_tw/more_announcement/-%E8%B3%87%E8%A8%8A%E8%99%95-%E8%BD%89%E7%9F%A5-ANA%E4%BA%8B%E4%BB%B6%E5%96%AE%E9%80%9A%E7%9F%A5-%E6%BC%8F%E6%B4%9E%E9%A0%90%E8%AD%A6-%E9%A9%8A%E9%89%85%E6%95%B8%E4%BD%8DEasy-Test-%E5%AD%98%E5%9C%A8%E6%BC%8F%E6%B4%9ECVE-2022-43436-CVE-2022-43437-CVE-2022-43438-69088418 https://keic.km.edu.tw/p/404-1017-13302.php https://www.twcert.org.tw/tw/lp-132-1-21-20.html https://net.nthu.edu.tw/netsys/mailing:announcement:20230104_04?do=export_pdf https://www.ctcn.edu.tw/ct_Bulletin_Basic.aspx?page=5&type=05&typename=%E8%B3%87%E8%A8%8A%E5%AE%89%E5%85%A8 https://net-edu.ylc.edu.tw/News_Content.aspx?n=108691&s=177455 https://www.twcert.org.tw/tw/lp-132-1-8-60.html https://140.120.1.20/news-detail/id/54834
Related VulnerabilitiesPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-53595: FreeScout < 1.8.224 - Invite Hash Authorization BypassPoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment DeletionPoCCVE-2026-34976: Dgraph <=v25.3.0 - Admin Mutation Missing AuthorizationPoCCVE-2026-1830: Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File UploadPoCCVE-2026-22683: Windmill < 1.603.3 - Operator Authorization BypassPoCCVE-2026-3335: Canto <= 3.1.1 - Missing Authorization to Unauthenticated File UploadPoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassPoCCVE-2025-68043: LottieFiles WordPress Plugin <= 3.0.0 - Missing AuthorizationPoCCVE-2024-30464: WPZOOM Social Icons Widget <= 4.2.15 - Missing AuthorizationPoCCVE-2025-11580: PowerJob List - Authorization BypassPoCCVE-2025-4210: Casdoor - Authorization Bypass