7.5
CVE-2022-23320
- EPSS 0.3%
- Veröffentlicht 07.02.2022 11:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:24
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xerox ≫ Xmpie Ustore Version12.3.7244.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.53 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.