PT-2023-15885 · Unknown · Evolution Events Artaxerxes

CVE-2022-4869

·

Published

2023-01-05

·

Updated

2024-05-17

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Evolution Events Artaxerxes (affected versions not specified)
Description A vulnerability was found in the component POST Parameter Handler, affecting unknown code of the file arta/common/middleware.py. The manipulation of the password argument leads to information disclosure. The attack can be initiated remotely.
Recommendations To fix this issue, it is recommended to apply a patch. The patch is identified as 022111407d34815c16c6eada2de69ca34084dc0d. As a temporary workaround, consider restricting access to the vulnerable component POST Parameter Handler until a patch is available. Avoid using the password argument in the affected middleware.py file until the issue is resolved.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4869

Affected Products

Evolution Events Artaxerxes