← Back to browse · API

CVE-2023-0104

Severity
CRITICAL
CVSS
9.3
EPSS
0.21846
Risk score
44.85
CISA KEV
No
PoC
No
Published
2023-02-22
Modified
2025-01-16
First seen
2026-08-07
Aliases
EUVD-2023-12202, GHSA-6JX2-8495-397P
Products
Weintek:EasyBuilder Pro cMT 0 ≤6.07.01, Weintek:EasyBuilder Pro cMT 0 ≤6.07.02.479, Weintek:EasyBuilder Pro cMT 0 ≤6.08.01.349
Sources
euvd EUVD-2023-12202

Description

The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.

References