9.8

CVE-2022-43019

Exploit
OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Opencats ≫ Opencats Version 0.9.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.04% 0.795
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://github.com/hansmach1ne/opencats_zero-days/blob/main/RCE_via_deserialisation.md
Third Party Advisory
Exploit
https://github.com/hansmach1ne/CVE-portfolio/tree/main/CVE-2022-43019
Third Party Advisory
Exploit