CVE-2024-25228 Information

Description

Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

Reference

https://blog.leakix.net/2024/01/vinchin-backup-rce-chain/ https://seclists.org/fulldisclosure/2024/Mar/15

Share on: