PT-2023-32796 · Tongda Oa · Tongda Oa

Martinzb

·

Published

2023-12-16

·

Updated

2024-05-17

·

CVE-2023-6885

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tongda OA versions 2017 up to 11.10
Description A critical issue affects an unknown functionality of the file general/vote/manage/delete.php. The manipulation of the DELETE STR argument leads to sql injection. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond.
Recommendations For Tongda OA versions 2017 up to 11.10, as a temporary workaround, consider restricting access to the delete.php file in the general/vote/manage directory to minimize the risk of exploitation. Avoid using the DELETE STR argument in the affected functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-6885

Affected Products

Tongda Oa