PT-2022-27309 · Unknown · Appalti & Contratti
Published
2022-11-21
·
Updated
2025-04-29
·
CVE-2022-44786
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Appalti & Contratti version 9.12.2
Description
An issue was discovered in the target web applications, allowing Local File Inclusion in any page relying on the
href parameter to specify the JSP page to be rendered. This affects ApriPagina.do POST and GET requests to each application.Recommendations
For Appalti & Contratti version 9.12.2, consider restricting access to the
href parameter in ApriPagina.do requests to minimize the risk of exploitation. As a temporary workaround, avoid using the href parameter to specify JSP pages until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appalti & Contratti