CVE-2023-4165 is a critical SQL injection vulnerability in Tongda OA, specifically affecting an unknown part of the general/system/seal_manage/iweboffice/delete_seal.php file. This flaw, rated 9.8 CVSS (Critical), allows unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) by manipulating the DELETE_STR argument. While not yet in CISA KEV, exploit code has been publicly disclosed, and the vulnerability has significant community discussion, indicating a high likelihood of exploitation. Organizations using Tongda OA are strongly advised to upgrade to version 11.10 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.10CPE matchmatch criteria | cpe:2.3:a:tongda2000:tongda_office_anywhere:11.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.