Anheng Information (Hangzhou DBAPP Security Information Technology Co., Ltd.) Vulnerabilities and Affected Products
Vulnerabilities associated with Mingyu Operations and Maintenance Audit and Risk Control System.
Products
Clear product| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-7325CRITICAL | Mingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRFAnheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts specially crafted XML-RPC requests that can be used to instruct the server to connect to internal unix socket RPC endpoints and perform privileged XML-RPC methods. An attacker able to send such requests can invoke administrative RPC methods via the unix socket interface to create arbitrary user accounts … | CVSS9.3v4.0 | EPSS0.378% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |