TOBESOFT XPLATFORM arbitrary hta file execution vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
TOBESOFT · XPLATFORM XPlatformLib922.dll