CVE-2022-27967

Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a crafted GET request sent to /WebApp/SettingsExclusion/GetExclusionsProfiles.
References
Link Resource
https://www.cynet.com/platform/ Vendor Advisory
https://www.srlabs.de/bites/edr-security Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:cynet:cynet_360:*:*:*:*:*:*:*:*

Information

Published : 2022-09-08 09:15

Updated : 2022-09-12 07:07


NVD link : CVE-2022-27967

Mitre link : CVE-2022-27967


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

cynet

  • cynet_360