vendor:
Edraw Office Viewer Component
by:
Cyber-Zone
9.3
CVSS
HIGH
Insecure Method
434
CWE
Product Name: Edraw Office Viewer Component
Affected Version From: v5.4
Affected Version To: v5.4
Patch Exists: Yes
Related CWE: N/A
CPE: a:edrawsoft:edraw_office_viewer_component
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Edraw Office Viewer Component v5.4 HttpDownloadFile() Insecure Method
Edraw Office Viewer Component v5.4 is vulnerable to an insecure method vulnerability. An attacker can exploit this vulnerability to download a malicious file from a remote server to the vulnerable system. This vulnerability is due to the HttpDownloadFile() method of the Edraw Office Viewer Component, which allows an attacker to download a file from a remote server to the vulnerable system without any authentication.
Mitigation:
Upgrade to the latest version of Edraw Office Viewer Component.