CVE-2022-39021 MEDIUM

CVE-2022-39021: e-Excellence Inc. U-Office Force - Open Redirect

Vendor E-Excellence Inc.
Product U-Office Force
Weakness CWE-601 · Open redirect
Published October 31, 2022
Last update May 6, 2025

CVSS base score

6.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user to arbitrary website.

Key dates

02Disclosure timeline

October 31, 2022 CVE published
May 6, 2025 Record updated