CVE-2023-1773 is a code-injection vulnerability in Rockoa 2.3.2 affecting unspecified code in the Configuration File Handler's webmainConfig.php component. Remote manipulation of the affected functionality can inject code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit for CVE-2023-1773, targeting the 信呼OA (Xinhu OA) collaborative office system. The repository consists of two files: a minimal README and a Python script (exp.py) that implements the exploit logic. The script performs several actions: it changes the admin password, logs in as admin, injects PHP code to create a web shell via a vulnerable API endpoint, and then executes arbitrary system commands (demonstrated with 'whoami'). The exploit leverages multiple HTTP endpoints of the target application, using custom encoding and session management to interact with the web application. The payload is a PHP code injection that enables remote code execution. The exploit is operational and demonstrates full compromise of the target system if successful.
This repository provides a complete Dockerized environment for Xinhu OA v2.3.2, specifically tailored for testing and exploiting CVE-2023-1773. The environment includes Dockerfiles, configuration for PHP, Nginx, and MySQL, as well as the full source code of Xinhu OA v2.3.2. The README and references indicate that this setup is intended for security research and CTF-style exploitation of the CVE. The main entry points are the web interface (exposed on port 8080) and the API endpoint (api.php). The repository includes scripts to initialize the database with test users and a flag, and the web application is configured for debugging and easy exploitation. No actual exploit script is included, but the environment is designed to facilitate manual or automated exploitation of the vulnerability. The codebase is primarily PHP, with supporting scripts in Bash, SQL, and JavaScript. The attack vector is network-based, targeting the web application over HTTP. The repository is not part of a framework and is a standalone environment for vulnerability research.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.