2025-09-29 16:08:36 +00:00
### [CVE-2024-37728](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37728)

2025-09-29 21:09:30 +02:00




2025-09-29 16:08:36 +00:00
### Description
Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface
### POC
#### Reference
- https://github.com/wy876/POC/blob/main/OfficeWeb365/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md
- https://github.com/xuetang1125/OfficeWeb365/blob/main/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20.md
#### Github
No PoCs found on GitHub currently.