CVE-2023-47418: Critical severity zhejiang land zongheng network technology o2oa vulnerability
Published Nov 30, 2023
·Updated
Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.
Affected Software
1 affected component
Zoneland O2oa<=8.1.2
Event History
Nov 30, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-47418?
CVE-2023-47418 is a critical Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before.
2
How does CVE-2023-47418 impact the affected software?
CVE-2023-47418 allows attackers to create a new interface in the service management function to execute JavaScript, potentially leading to unauthorized code execution.
3
What is the severity of CVE-2023-47418?
CVE-2023-47418 has a severity rating of 9.8 (Critical).
4
Which software version is affected by CVE-2023-47418?
o2oa version 8.1.2 and before is affected by CVE-2023-47418.
5
How can I fix the CVE-2023-47418 vulnerability?
To fix the CVE-2023-47418 vulnerability, update o2oa to a version that is after 8.1.2.