CVE Database
/

CVE-2023-5296

Back to search

CVE-2023-5296

Published: Sep 29, 2023

Modified: Sep 23, 2024

PUBLISHED

CVSS v3.1

4.3

MEDIUM

Description

A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation leads to weak password recovery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240926 is the identifier assigned to this vulnerability.

VendorProductVersions

Xinhu

RockOA

affected
1.1
affected
2.3.2
affected
15.X3amdi

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

Low

Availability

None

References

https://vuldb.com/?id.240926
vdb-entry
technical-description
https://vuldb.com/?ctiid.240926
signature
permissions-required

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now