{"cve":"CVE-2023-7334","enrichment":{"created":"2026-01-16T13:43:06.585193+00:00","updated":"2026-01-16T13:43:06.585285+00:00","vendors":["changjetong","changjetong$PRODUCT$t+"]},"epss":{"score":0.01115},"mitre":{"cpes":["cpe:2.3:a:chanjetvip:t\\+:*:*:*:*:*:*:*:*"],"created":"2026-01-15T21:44:58.843000+00:00","description":"Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2023/7xxx/CVE-2023-7334.json","references":["https://blog.csdn.net/qq_53003652/article/details/134031230","https://blog.csdn.net/u010025272/article/details/131553591","https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py","https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62","https://www.freebuf.com/articles/web/381731.html","https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce"],"title":"Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE","updated":"2026-05-14T02:07:07.753000+00:00","vendors":["chanjetvip","chanjetvip$PRODUCT$t\\+"],"weaknesses":["CWE-502"]},"nvd":{"cpes":["cpe:2.3:a:chanjetvip:t\\+:*:*:*:*:*:*:*:*"],"created":"2026-01-15T22:16:10.180000+00:00","description":"Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2023/CVE-2023-7334.json","references":["https://blog.csdn.net/qq_53003652/article/details/134031230","https://blog.csdn.net/u010025272/article/details/131553591","https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py","https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62","https://www.freebuf.com/articles/web/381731.html","https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce"],"title":null,"updated":"2026-06-17T06:52:33.137000+00:00","vendors":["chanjetvip","chanjetvip$PRODUCT$t\\+"],"weaknesses":["CWE-502"]},"opencve":{"changes":[{"created":"2026-01-15T22:00:00+00:00","data":[{"details":{"new":"Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation on 2023-08-19 (UTC).","old":null},"type":"description"},{"details":{"new":"Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE","old":null},"type":"title"},{"details":{"added":["CWE-502"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://blog.csdn.net/qq_53003652/article/details/134031230","https://blog.csdn.net/u010025272/article/details/131553591","https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py","https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62","https://www.freebuf.com/articles/web/381731.html","https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"ff2c8760-2b7f-45ee-a000-89b904044193"},{"created":"2026-01-16T14:15:00+00:00","data":[{"details":["changjetong","changjetong$PRODUCT$t+"],"type":"first_time"},{"details":{"added":["changjetong","changjetong$PRODUCT$t+"],"removed":[]},"type":"vendors"}],"id":"c3417196-9642-4d8c-bdbf-c0e4e27097b6"},{"created":"2026-01-20T16:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"b5403cdf-5153-45f0-8c58-f0ab5f910091"},{"created":"2026-01-21T21:45:00+00:00","data":[{"details":{"new":"Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).","old":"Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation on 2023-08-19 (UTC)."},"type":"description"}],"id":"b96c9291-5a18-4c50-a1c0-f0b2ee068c98"},{"created":"2026-01-23T20:00:00+00:00","data":[{"details":["chanjetvip","chanjetvip$PRODUCT$t\\+"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:chanjetvip:t\\+:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["chanjetvip","chanjetvip$PRODUCT$t\\+"],"removed":[]},"type":"vendors"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"1689beda-1c17-4894-b24c-58c84116fab1"}],"cpes":{"data":["cpe:2.3:a:chanjetvip:t\\+:*:*:*:*:*:*:*:*"],"providers":["mitre","nvd"]},"created":{"data":"2026-01-15T21:44:58.843000+00:00","provider":"mitre"},"description":{"data":"Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV4_0":{"data":{"score":9.3,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.01115},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://blog.csdn.net/qq_53003652/article/details/134031230","https://blog.csdn.net/u010025272/article/details/131553591","https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py","https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62","https://www.freebuf.com/articles/web/381731.html","https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":"Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE","provider":"mitre"},"updated":{"data":"2026-03-23T15:43:30.546000+00:00","provider":"mitre"},"vendors":{"data":["changjetong","changjetong$PRODUCT$t+","chanjetvip","chanjetvip$PRODUCT$t\\+"],"providers":["mitre","nvd","enrichment"]},"weaknesses":{"data":["CWE-502"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2026-01-15T21:44:58.843000+00:00","description":"Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":["https://www.freebuf.com/articles/web/381731.html"],"title":"Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE","updated":"2026-01-20T15:58:29.716000+00:00","vendors":[],"vulnrichment_repo_path":"2023/7xxx/CVE-2023-7334.json","weaknesses":[]}}