PT-2023-30446 · O2Oa · O2Oa

Onlyning

·

Published

2023-11-30

·

Updated

2023-12-05

·

CVE-2023-47418

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions o2oa versions 8.1.2 and earlier
Description The issue allows attackers to create a new interface in the service management function to execute JavaScript, enabling Remote Code Execution (RCE).
Recommendations For versions 8.1.2 and earlier, consider disabling the service management function temporarily to prevent the creation of new interfaces that could be used for JavaScript execution until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-47418

Affected Products

O2Oa