HIGH
Xinhu RockOA Password password recovery
Published Sep 29, 2023
7.5
HIGHCVSS 3.1
EPSS 0.51%
Description
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation leads to weak password recovery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240926 is the identifier assigned to this vulnerability.
Affected products
-
- Version 1.1StatusaffectedConstraints-
- Version 15.X3amdiStatusaffectedConstraints-
- Version 2.3.2StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57619 Advisory
- https://github.com/magicwave18/vuldb/issues/1 exploitissue-trackingIssue Tracking
- https://vuldb.com/?ctiid.240926 signaturepermissions-requiredPermissions RequiredThird Party Advisory
- https://vuldb.com/?id.240926 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57619 | Advisory | |
| https://github.com/magicwave18/vuldb/issues/1 | exploitissue-trackingIssue Tracking | |
| https://vuldb.com/?ctiid.240926 | signaturepermissions-requiredPermissions RequiredThird Party Advisory | |
| https://vuldb.com/?id.240926 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 29, 2023
Updated Sep 23, 2024
Reserved Sep 29, 2023
Link CVE-2023-5296
CISA Vulnrichment
Updated Sep 23, 2024
ENISA EUVD
EUVD-2023-57619 Assigner VulDB
Published Sep 29, 2023
Updated Sep 23, 2024
Exploited since n/a
Link EUVD-2023-57619