CVE-2022-45326

An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
References
Link Resource
https://www.navsec.net/2022/11/12/kwoksys-xxe.html Exploit Patch Third Party Advisory
http://www.kwoksys.com/wiki/index.php?title=Release_Notes Release Notes Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kwoksys:information_server:2.9.5:sp25:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp26:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp29:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp30:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:*:*:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp23:*:*:*:*:*:*

Information

Published : 2022-12-06 09:15

Updated : 2022-12-08 08:34


NVD link : CVE-2022-45326

Mitre link : CVE-2022-45326


JSON object : View

CWE
CWE-611

Improper Restriction of XML External Entity Reference

Advertisement

dedicated server usa

Products Affected

kwoksys

  • information_server