CVE-2022-47075
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
7.5
CVSS
59.4%
EPSS (exploit prob.)
99th
EPSS percentile
2023-02-28
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| smartofficepayroll | smartoffice | <= 20.28 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/173093/Smart-Office-Web-20.28-Information-Disclosure-Insecure-Direct-Object-Reference.html
- https://cvewalkthrough.com/smart-office-suite-cve-2022-47076-cve-2022-47075/
- https://cvewalkthrough.com/smart-office-suite-unauthenticated-data-ex/
- https://youtu.be/D42upepxzwM
- http://packetstormsecurity.com/files/173093/Smart-Office-Web-20.28-Information-Disclosure-Insecure-Direct-Object-Reference.html
- https://cvewalkthrough.com/smart-office-suite-cve-2022-47076-cve-2022-47075/
- https://cvewalkthrough.com/smart-office-suite-unauthenticated-data-ex/
- https://youtu.be/D42upepxzwM
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-47075