PT-2024-1553 · Vinchin · Vinchin Backup & Recovery

Valentin Lobstein

·

Published

2024-01-11

·

Updated

2025-06-04

·

CVE-2024-22899

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vinchin Backup & Recovery version 7.2
Description The issue is related to the syncNtpTime() function in the SystemHandler.class.php script of Vinchin Backup & Recovery, which fails to neutralize special elements used in the operating system command when processing the ntphost parameter. This can be exploited by a remote attacker to execute arbitrary commands by sending specially crafted POST requests. The vulnerability allows for authenticated remote code execution (RCE) via the syncNtpTime function.
Recommendations For Vinchin Backup & Recovery version 7.2, as a temporary workaround, consider disabling the syncNtpTime() function until a patch is available. Restrict access to the SystemHandler.class.php script to minimize the risk of exploitation. Avoid using the ntphost parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Code Injection

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-01094
CVE-2024-22899

Affected Products

Vinchin Backup & Recovery