PT-2022-28016 · Passhunt · Passhunt

Di1L0O

·

Published

2022-12-14

·

Updated

2025-04-21

·

CVE-2022-46997

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867
Description The issue allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges via a code execution backdoor in the request package.
Recommendations For Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867, consider removing or disabling the vulnerable code to prevent exploitation until a fixed version is available. As a temporary workaround, restrict access to sensitive user information and digital currency keys to minimize the risk of unauthorized access.

Exploit

Fix

Hidden Functionality

Weakness Enumeration

Related Identifiers

CVE-2022-46997

Affected Products

Passhunt