PT-2023-30446 · O2Oa · O2Oa

Onlyning

·

Publicado

2023-11-30

·

Atualizado

2023-12-05

·

CVE-2023-47418

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions o2oa versions 8.1.2 and earlier
Description The issue allows attackers to create a new interface in the service management function to execute JavaScript, enabling Remote Code Execution (RCE).
Recommendations For versions 8.1.2 and earlier, consider disabling the service management function temporarily to prevent the creation of new interfaces that could be used for JavaScript execution until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-47418

Produtos afetados

O2Oa