Executive brief
eGovFramework is a standardized development platform widely used for South Korean government IT projects. A security flaw in its Web Editor component allows unauthorized users to trick the system into generating valid encrypted tokens for data they control. An attacker can use these tokens to bypass security checks and access sensitive files stored on the server that should otherwise be protected.
Technical details
The vulnerability exists in the Web Editor image upload endpoints (/utl/wed/insertImage.do and /utl/wed/insertImageCk.do) which use symmetric encryption to protect URL parameters such as server-side paths and filenames. Because these endpoints return the resulting ciphertext to the client and other endpoints (like /utl/web/imageSrc.do) trust these encrypted parameters without further validation, the system acts as an encryption oracle. An unauthenticated attacker can provide arbitrary values to the upload endpoints to obtain their encrypted representations and then replay that ciphertext to file-serving APIs to retrieve arbitrary stored files, bypassing access controls. As of the advisory date, the vulnerability is reported as unpatched in versions up to 4.3.1.
Affected products
- eGovFramework egovframe-common-components up to and including 4.3.1
Timeline
- 2023-03: disclosed: Vulnerability discovered by researcher
- 2023-04-01: disclosed: Reported to KrCERT via POC Security
- 2023-08-01: other: KISA confirmed vulnerability is exploitable
- 2025-11-19: advisory: CVE-2025-34337 assigned and published by VulnCheck
References
- https://github.com/eGovFramework/egovframe-common-components
- https://pierrekim.github.io/advisories/2025-egovframe.txt
- https://pierrekim.github.io/blog/2025-11-20-egovframe-2-vulnerabilities.html
- https://www.egovframe.go.kr/eng/sub.do?menuNo=2
- https://www.vulncheck.com/advisories/egovframework-unauthenticated-encryption-oracle-via-web-editor-image-upload-endpoints