PT-2024-1552 · Vinchin · Vinchin Backup & Recovery

Valentin Lobstein

·

Published

2024-01-11

·

Updated

2024-02-13

·

CVE-2024-22903

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vinchin Backup & Recovery version 7.2
Description The issue is related to an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK() function. This vulnerability can be exploited by sending specially crafted POST requests, allowing a remote attacker to execute arbitrary commands. The vulnerability is associated with the failure to neutralize special elements used in the operating system command when processing the file name parameter.
Recommendations For Vinchin Backup & Recovery version 7.2, consider disabling the deleteUpdateAPK() function as a temporary workaround until a patch is available. Restrict access to the vulnerable function to minimize the risk of exploitation. Avoid using the file name parameter in affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-01093
CVE-2024-22903

Affected Products

Vinchin Backup & Recovery