References https://www.twcert.org.tw/newepaper/cp-151-7328-d4112-3.html https://www.twcert.org.tw/en/cp-139-7390-c5244-2.html https://cve.imfht.com/detail/CVE-2023-32755 https://www.cve.org/CVERecord?id=CVE-2023-32755 https://github.com/advisories/GHSA-mx95-7g4v-pppj https://www.clouddefense.ai/cve/2023/CVE-2023-32755 https://www.twcert.org.tw/tw/lp-132-1-7-60.html https://cve.imfht.com/vendor/e-Excellence?lang=en
Related VulnerabilitiesPoCCVE-2026-8237: Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)金和OA /c6/JHSoft.Web.CostControl/Decompose/AjaxForCenterBudgetDecompose.ashx SQL 注入漏洞PoCdzzoffice-installer: DzzOffice - Installer Page ExposureProgress WhatsUp Gold /NmConsole/Platform/PerformanceMonitorErrors/HasErrors SQL 注入漏洞(CVE-2024-6670)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)智联云采 SRM2.0 /a/sys/sysMessage/statusList SQL 注入漏洞上海必智科技有限公司律师E通userID和officeID参数存在SQL注入漏洞PoCretool-postmessage-xss: Retool Self-Hosted - postMessage XSS via Custom Component Collections友訊科技|DWM-222W Wi-Fi 6 USB 行動網路卡 - Brute-Force Protection Bypass泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞PoCCVE-2025-53533: Pi-hole Reflected XSS in 404-Error Page