📦 Office Anywhere

by Tongda2000

🔍 What is Office Anywhere?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-25320

CRITICAL CVSS 9.8 Feb 16, 2024

This CVE describes a SQL injection vulnerability in Tongda OA software that allows attackers to execute arbitrary SQL commands via the $AFF_ID parameter in the /affair/delete.php endpoint. Organizatio...

CVE-2024-10600

HIGH CVSS 7.3 Oct 31, 2024

This critical SQL injection vulnerability in Tongda OA allows remote attackers to execute arbitrary SQL commands through the appid parameter in pda/appcenter/submenu.php. Organizations using Tongda OA...

CVE-2024-10731

MEDIUM CVSS 6.3 Nov 3, 2024

This critical SQL injection vulnerability in Tongda OA allows remote attackers to execute arbitrary SQL commands via the ID parameter in /pda/appcenter/check_seal.php. This could lead to data theft, m...

CVE-2024-10658

MEDIUM CVSS 6.3 Nov 1, 2024

This critical SQL injection vulnerability in Tongda OA allows remote attackers to execute arbitrary SQL commands via the ID parameter in /pda/approve_center/check_seal.php. Organizations using Tongda ...

CVE-2024-10656

MEDIUM CVSS 6.3 Nov 1, 2024

This critical SQL injection vulnerability in Tongda OA 2017 allows remote attackers to execute arbitrary SQL commands via the mr_id parameter in /pda/meeting/apply.php. Organizations using Tongda OA 2...

CVE-2024-10618

MEDIUM CVSS 6.3 Nov 1, 2024

This critical SQL injection vulnerability in Tongda OA 2017 allows remote attackers to execute arbitrary SQL commands via the repid parameter in /pda/reportshop/record_detail.php. Organizations using ...

CVE-2024-10616

MEDIUM CVSS 6.3 Nov 1, 2024

This critical SQL injection vulnerability in Tongda OA allows remote attackers to execute arbitrary SQL commands by manipulating the saleId parameter in the /pda/workflow/webSignSubmit.php file. Organ...

CVE-2024-10602

MEDIUM CVSS 6.3 Nov 1, 2024

This CVE describes a critical SQL injection vulnerability in Tongda OA 2017 through version 11.9. Attackers can exploit the /general/approve_center/list/input_form/data_picker_link.php file by manipul...

CVE-2024-10598

MEDIUM CVSS 5.3 Oct 31, 2024

This critical vulnerability in Tongda OA allows attackers to bypass authorization controls in the annual leave management component, potentially accessing or manipulating sensitive HR data. It affects...