CVE-2023-7325 Details
Description
Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts specially crafted XML-RPC requests that can be used to instruct the server to connect to internal unix socket RPC endpoints and perform privileged XML-RPC methods. An attacker able to send such requests can invoke administrative RPC methods via the unix socket interface to create arbitrary user accounts on the system, resulting in account creation and potential takeover of the bastion host. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-30 at 00:30:17.837319 UTC.
A server-side request forgery (SSRF) vulnerability has been identified in the Anheng Mingyu Operation and Maintenance Audit and Risk Control System, in versions prior to 2023-08-10. The vulnerability resides in the XML-RPC handler for Unix socket communication. It allows attackers to send specially crafted XML-RPC requests that can manipulate the server into connecting to internal Unix socket RPC endpoints and executing privileged XML-RPC methods. Exploitation of this vulnerability enables the creation of arbitrary user accounts on the system, potentially leading to unauthorized access and control over the bastion host.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 30, 2025CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Anheng Mingyu Operation and Maintenance Audit and Risk Control System | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | New CVE Received | [email protected] |
Volerion