Sept. 29, 2023, 10:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240927.

amp attack backup classified complexity control cve exposure file found function high manipulation php sphere start task vulnerability

Network Security Tools Engineer / Systems Engineer

@ Node.Digital | Arlington, Virginia, United States

Scrum Master II - Global Information Security PMO

@ Marriott International | Bethesda, MD, United States

Principle Security Incident Response Analyst

@ Oracle | United States

Cyber Network Engineer

@ Peraton | Aberdeen Proving Ground, MD, United States

Red Team Operator: Assessments & Exercises Vice President

@ JPMorgan Chase & Co. | Columbus, OH, United States

Cybersecurity Undergraduate - Internship

@ esure Group | Reigate, United Kingdom