EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinkingsoftware
Thinkingsoftware efence |
|
| Vendors & Products |
Thinkingsoftware
Thinkingsoftware efence |
Wed, 26 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | Thinking Software Technology|EFence - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2026-08-26T08:26:12.960Z
Updated: 2026-08-26T13:57:37.398Z
Reserved: 2026-08-26T05:58:51.131Z
Link: CVE-2026-80235
Updated: 2026-08-26T13:57:34.678Z
Status : Deferred
Published: 2026-08-26T09:16:49.027
Modified: 2026-08-26T16:40:21.650
Link: CVE-2026-80235
No data.