CVE-2002-0583: Workforceroi Xpede

Medium severity, CVSS 5.0. EPSS: 1.6% chance of exploitation in the next 30 days.

WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports via a brute force attack.

Affected products

Published 2002-06-18. Last modified 2026-06-16.