CVE-2023-7325
Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The product accepts specially crafted XML-RPC requests that can be used to instruct the server to connect to internal unix socket RPC endpoints and perform privileged XML-RPC methods. An attacker able to send such requests can invoke administrative RPC methods via the unix socket interface to create arbitrary user accounts on the system, resulting in account creation and potential takeover of the bastion host. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-30 at 00:30:17.837319 UTC.
Published:Oct 30, 2025
Last Modified:Jul 28, 2026
EPS:Oct 30, 2025
EPSS Score:0.00378
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Anheng Information
Product
Mingyu Operations And Maintenance Audit And Risk Control System
Anheng Information
Mingyu Operations And Maintenance Audit And Risk Control System
Vendor
Kubernetes
Product
Operations
Kubernetes
Operations
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
