🔐 CVE Alert

CVE-2023-7325

UNKNOWN 0.0

Mingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRF

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts specially crafted XML-RPC requests that can be used to instruct the server to connect to internal unix socket RPC endpoints and perform privileged XML-RPC methods. An attacker able to send such requests can invoke administrative RPC methods via the unix socket interface to create arbitrary user accounts on the system, resulting in account creation and potential takeover of the bastion host. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-30 at 00:30:17.837319 UTC.

CWE CWE-306 CWE-918
Vendor anheng information (hangzhou dbapp security information technology co., ltd.)
Product mingyu operations and maintenance audit and risk control system
Published Oct 30, 2025
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for anheng information (hangzhou dbapp security information technology co., ltd.) mingyu operations and maintenance audit and risk control system

Be the first to know when new unknown vulnerabilities affecting anheng information (hangzhou dbapp security information technology co., ltd.) mingyu operations and maintenance audit and risk control system are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Anheng Information (Hangzhou DBAPP Security Information Technology Co., Ltd.) / Mingyu Operations and Maintenance Audit and Risk Control System
0 < 2023-08-10

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cn-sec.com: https://cn-sec.com/archives/1947658.html github.com: https://github.com/PeiQi0/PeiQi-WIKI-Book/blob/main/docs/wiki/iot/%E5%AE%89%E6%81%92/%E5%AE%89%E6%81%92%20%E6%98%8E%E5%BE%A1%E8%BF%90%E7%BB%B4%E5%AE%A1%E8%AE%A1%E4%B8%8E%E9%A3%8E%E9%99%A9%E6%8E%A7%E5%88%B6%E7%B3%BB%E7%BB%9F%20xmlrpc.sock%20%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E6%B7%BB%E5%8A%A0%E6%BC%8F%E6%B4%9E.md vulncheck.com: https://www.vulncheck.com/advisories/mingyu-operations-and-maintenance-audit-and-risk-control-system-xmirpc-sock-ssrf

Credits

Anonymous User via CN-SEC