CVE-2023-7325 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Anheng Mingyu Operation and Maintenance Audit and Risk Control System versions up to 2023-08-10. This flaw allows unauthenticated attackers to send specially crafted XML-RPC requests to the xmlrpc.sock handler, enabling them to invoke administrative RPC methods via internal unix sockets. Successful exploitation can lead to arbitrary user account creation and potential takeover of the bastion host, with a CVSS score of 9.3 (CRITICAL). This vulnerability is actively being exploited in the wild, as observed by VulnCheck, despite a lack of public exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Anheng Information (Hangzhou DBAPP Security Information Technology Co., Ltd.) | Mingyu Operations And Maintenance Audit And Risk Control System | >= 0, < 2023-08-10CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.