CNNVD-202508-668 Information

CNNVD ID

CNNVD-202508-668

CVE-2024-42048

  • CNNVD Published: 2025-08-07

Description (Chinese)

OpenOrange Business Framework是OpenOrange公司的一个业务应用框架。 OpenOrange Business Framework 1.15.5版本存在安全漏洞,该漏洞源于向非特权用户提供对安装目录的写访问权限。

Description (English)

OpenOrange Business Platform is a business application framework for OpenOrange. The security gap in version 1.15.5 of OpenOrange Business Platform stems from the provision of written access to installed directories to non-privileged users.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

OpenOrange

Published

2025-08-07

Last Modified

2026-02-24

References

https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibrarya https://www.openorange.com https://support.microsoft.com/en-us/topic/secure-loading-of-libraries-to-prevent-dll-preloading-attacks-d41303ec-0748-9211-f317-2edc819682e1 https://raw.githubusercontent.com/securityadvisories/Security-Advisories/refs/heads/main/Advisories/Blaze%20Information%20Security%20-%20DLL%20Hijacking%20in%20OpenOrange%20Business%20Framework%20Allows%20Arbitrary%20Code%20Execution%20and%20Potential%20Privilege%20Escalation.txt https://docs.microsoft.com/en-us/windows/win32/dlls/dynamic-link-library-search-order https://docs.microsoft.com/en-us/windows/win32/api/libloaderapi/nf-libloaderapi-loadlibraryexa https://resources.infosecinstitute.com/topic/dll-hijacking https://landings.openorange.com/l/erp-peru-a.html https://attack.mitre.org/techniques/T1574/001 https://nvd.nist.gov/vuln/detail/CVE-2024-42048

Share on: