漏洞标题
yinhu rockOA 开始备份
漏洞描述信息
新华岩石OA开始备份
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
将资源暴露给错误范围
漏洞标题
Xinhu RockOA start backup
漏洞描述信息
A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240927.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
将备份文件暴露给非授权控制范围
漏洞标题
RockOA 安全漏洞
漏洞描述信息
RockOA(信呼)是一套开源的办公OA系统。 Xinhu RockOA 2.3.2版本存在安全漏洞。攻击者利用该漏洞导致备份文件暴露给未经授权的控制范围。
CVSS信息
N/A
漏洞类别
其他