Junglewise Threat Intelligence

CVE-2025-34336: eGovFramework egovframe-common-components unauthenticated file upload in web editor

CVE-2025-34336 · Severity: info · CVSS 6.9 · Published 2025-11-19

Executive brief

eGovFramework is a standardized development platform widely used for public sector IT projects and government websites in South Korea. A security flaw in its common components allows unauthorized users to upload files to a server without providing any login credentials. This could allow an attacker to use a government website to host malicious content, such as phishing pages or scripts designed to steal user data.

Technical details

An unauthenticated file upload vulnerability exists in eGovFramework/egovframe-common-components versions up to and including 4.3.1. The vulnerability is located in the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do endpoints within EgovWebEditorImageController.java, which accept multipart POST requests without authentication. While the framework enforces a filename extension whitelist, it does not validate file contents, allowing attackers to upload arbitrary data. In versions prior to 4.1.2, attackers could also control the response MIME type; in later versions, non-image files are served as 'application/octet-stream'. This allows the application to be used as a persistent file hosting service for arbitrary content under the application's origin.

Affected products

  • eGovFramework egovframe-common-components up to and including 4.3.1

Timeline

  • 2023-03: disclosed: Vulnerability discovered by researcher Pierre Kim
  • 2023-04: disclosed: Reported to KrCERT via POC Security
  • 2023-08: other: KISA confirmed vulnerability is exploitable
  • 2023-10-01: patched: KISA confirmed vulnerabilities were patched (later found to be incomplete)
  • 2025-11-19: advisory: CVE-2025-34336 published

References

Related threats