An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
References
Link | Resource |
---|---|
https://cvewalkthrough.com/smart-office-suite-cve-2022-47076-cve-2022-47075/ | Exploit Third Party Advisory |
https://cvewalkthrough.com/smart-office-suite-unauthenticated-data-ex/ | Broken Link |
https://youtu.be/D42upepxzwM | Permissions Required |
Configurations
Information
Published : 2023-02-28 15:15
Updated : 2023-03-06 06:47
NVD link : CVE-2022-47075
Mitre link : CVE-2022-47075
JSON object : View
CWE
Products Affected
smartofficepayroll
- smartoffice