S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 15, 2025

CVE-2024-37728 Scanner

CVE-2024-37728 Scanner - Arbitrary File Read vulnerability in OfficeWeb365

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-37728
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
officeweb365by officeweb365
7.18.23.0
officeweb365by officeweb365
8.6.1.0
Updated Sep 10, 2026View on NVD →
Detail

OfficeWeb365 is a widely used online platform that allows users to access and manage their documents through a web interface. It is mainly used by businesses, educational institutions, and individuals who require online office applications. This platform provides functionalities such as text editing, data management, and presentation creation. Users appreciate its capabilities for team collaboration and document sharing, facilitating remote work and learning. It integrates seamlessly with various device platforms, enhancing accessibility and convenience for users globally.

The detected vulnerability in OfficeWeb365 is an Arbitrary File Read, which poses a significant risk. Arbitrary File Read vulnerabilities allow attackers to read files on the server without authorization. This can lead to the exposure of sensitive information or credentials stored on the server. The vulnerability could be exploited remotely without user authentication, making it accessible for attackers. Such vulnerabilities highlight weaknesses in access control and input validation mechanisms.

The technical details of the vulnerability involve the OfficeWeb365 Indexs interface. It allows remote attackers to send crafted GET requests to read files, using predictable file paths or filenames. The vulnerable endpoint is '/Pic/Indexs', and attackers manipulate the 'imgs' parameter to access unauthorized files. Successful exploitation relies on knowing or guessing valid filenames and paths on the server.

Exploitation of this vulnerability could lead to leakage of configuration files, user data, or other sensitive files. This could compromise user privacy, lead to identity theft, or enable further attacks on the network. In severe cases, sensitive system files could be read, exposing secrets that could escalate the attack to a more critical level. Organizations using OfficeWeb365 are at risk if this vulnerability is unpatched.

REFERENCES

Solution Advice
  • Update the OfficeWeb365 software to the latest version, if available.
  • Implement strict access control lists to restrict file access to authorized personnel only.
  • Conduct regular security audits and penetration tests to identify potential vulnerabilities.
  • Ensure proper input validation is implemented to prevent unauthorized file access.
  • Monitor application logs for any suspicious file access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.