Description
Police Statistics Database System developed by Gotac has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attacker to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
References
https://www.twcert.org.tw/en/cp-139-10638-0e44b-2.html
Third Party Advisory
https://www.twcert.org.tw/tw/cp-132-10637-3e4b3-1.html
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-16T03:16:18.817Z
1 month agoLast modified
2026-01-23T20:24:35.707Z
3 weeks ago