CVE-2025-34337
eGovFramework/egovframe-common-components
eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption oracle that allows attackers to generate valid ciphertext for chosen values. The image upload endpoints /utl/wed/insertImage.do and /utl/wed/insertImageCk.do encrypt server-side paths, filenames, and MIME types and embed them directly into a download URL that is returned to the client. Because these same encrypted parameters are trusted by other endpoints, such...
- CVSS
- 8.7
- EPSS
- 0.27% 19.7% percentile
- CISA KEV
- Not listed
- Published
- 2025.11.20