PT-2022-27309 · Unknown · Appalti & Contratti

Published

2022-11-21

·

Updated

2025-04-29

·

CVE-2022-44786

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Appalti & Contratti version 9.12.2
Description An issue was discovered in the target web applications, allowing Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do POST and GET requests to each application.
Recommendations For Appalti & Contratti version 9.12.2, consider restricting access to the href parameter in ApriPagina.do requests to minimize the risk of exploitation. As a temporary workaround, avoid using the href parameter to specify JSP pages until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2022-44786

Affected Products

Appalti & Contratti