CVE-2026-2672
MED 4.3A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function Download of the file /Search/Subject/downLoad. Performing a manipulation of the argument path results in path traversal. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Applications in Environment
10
Electron
v11.3.0
2 devices
Electron
v41.1.0
1 device
Electron
v22.0.2
1 device
Electron
v33.4.11
1 device
Electron
v40.7.0
2 devices
Electron
v35.0.2
1 device
Electron
v2.6.44.0
1 device
Electron
v36.3.2
1 device
Electron
v2.6.24.0
1 device
Electron
v2.7.12.0
1 device