CVE-2023-5296: Xinhu RockOA Password password recovery
A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of the file api.php?m=reimplat&a=index of the component Password Handler. The manipulation leads to weak password recovery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240926 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5296?
CVE-2023-5296 is classified as a problematic vulnerability affecting certain versions of RockOA.
How do I fix CVE-2023-5296?
To mitigate CVE-2023-5296, users should update to the latest version of RockOA where the vulnerability has been addressed.
Which versions of RockOA are affected by CVE-2023-5296?
CVE-2023-5296 affects versions 1.1, 2.3.2, and 15.x3amdi of RockOA.
What component is impacted by CVE-2023-5296?
CVE-2023-5296 impacts the Password Handler component specifically through the file api.php?m=reimplat&a=index.
What is the nature of the issue in CVE-2023-5296?
CVE-2023-5296 leads to weak password recovery mechanisms, which may be exploited by attackers.