Posting Date: 2026/09/03
【Vulnerability Alert】Think Software Technology|EFence - Arbitrary File Upload
- Subject: 【Vulnerability Alert】Think Software Technology|EFence - Arbitrary File Upload
- Content:
- Forwarded from Taiwan Computer Emergency Response Team/Coordination Center Security Alert TWCERTCC-200-202608-00000020
- 【Think Software Technology|EFence - Arbitrary File Upload】(CVE-2026-80235, CVSS: 9.8) An unauthenticated remote attacker can upload and execute web webshells, thereby executing arbitrary code on the server side.
- 【Think Software Technology|EFence - Arbitrary File Upload】(CVE-2026-80237, CVSS: 8.8) An authenticated remote attacker can upload and execute web webshells, thereby executing arbitrary code on the server side.
- Affected Platforms:
- EFence version 1.2.66 DB Ver:56 and earlier versions
- Recommendations:
- Please update to version 1.2.67 DB Ver:57 or later
- References:
Computer and Communication Center
Network System Division Respectfully