Executive brief
eGovFramework is a standardized development platform widely used for public sector IT projects and government websites in South Korea. A security flaw in its common components allows unauthorized users to upload files to a server without providing any login credentials. This could allow an attacker to use a government website to host malicious content, such as phishing pages or scripts designed to steal user data.
Technical details
An unauthenticated file upload vulnerability exists in eGovFramework/egovframe-common-components versions up to and including 4.3.1. The vulnerability is located in the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do endpoints within EgovWebEditorImageController.java, which accept multipart POST requests without authentication. While the framework enforces a filename extension whitelist, it does not validate file contents, allowing attackers to upload arbitrary data. In versions prior to 4.1.2, attackers could also control the response MIME type; in later versions, non-image files are served as 'application/octet-stream'. This allows the application to be used as a persistent file hosting service for arbitrary content under the application's origin.
Affected products
- eGovFramework egovframe-common-components up to and including 4.3.1
Timeline
- 2023-03: disclosed: Vulnerability discovered by researcher Pierre Kim
- 2023-04: disclosed: Reported to KrCERT via POC Security
- 2023-08: other: KISA confirmed vulnerability is exploitable
- 2023-10-01: patched: KISA confirmed vulnerabilities were patched (later found to be incomplete)
- 2025-11-19: advisory: CVE-2025-34336 published
References
- https://github.com/eGovFramework/egovframe-common-components
- https://pierrekim.github.io/advisories/2025-egovframe.txt
- https://pierrekim.github.io/blog/2025-11-20-egovframe-2-vulnerabilities.html
- https://www.egovframe.go.kr/eng/sub.do?menuNo=2
- https://www.vulncheck.com/advisories/egovframework-unauthenticated-file-upload-via-web-editor-image-upload-endpoints