PT-2023-15155 · Unknown · Smart Office Web
Tejas Nitin Pingulkar
·
Publicado
2023-02-28
·
Atualizado
2025-03-18
·
CVE-2022-47076
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Smart Office Web versions 20.28 and earlier
Description
An issue was discovered that allows attackers to view sensitive information via the "DisplayParallelLogData.aspx" API endpoint.
Recommendations
For versions 20.28 and earlier, consider restricting access to the "DisplayParallelLogData.aspx" endpoint until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Smart Office Web