Tongda OA 2017 delete_all.php sql injection
CVE-2023-7022
Key Information:
Badges
Summary
A vulnerability exists in Tongda OA 2017 affecting versions up to 11.9, specifically within the file general/work_plan/manage/delete_all.php. This vulnerability allows for SQL injection through manipulation of the DELETE_STR argument. The exploit can be executed remotely, posing a significant risk to data integrity and security. The vendor has been notified but has not responded to the disclosure. This situation raises concerns about the ongoing security of the software, emphasizing the need for immediate attention by users to safeguard their systems.
Affected Version(s)
OA 2017 11.0
OA 2017 11.1
OA 2017 11.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved