Vinchin Backup And Recovery Command Injection

Discussion in 'News Aggregator' started by Packet Storm, 22 Dec 2023.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a command injection vulnerability in Vinchin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.*. Due to insufficient input validation in the checkIpExists API endpoint, an attacker can execute arbitrary commands as the web server user.

    Continue reading...
     

Share This Page

Loading...