Описание
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
Ссылки
- ExploitThird Party Advisory
- Broken Link
- Permissions Required
- ExploitThird Party Advisory
- Broken Link
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия до 20.28 (включая)
cpe:2.3:a:smartofficepayroll:smartoffice:*:*:*:*:web:*:*:*
EPSS
Процентиль: 100%
0.92526
Критический
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
github
почти 3 года назад
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
EPSS
Процентиль: 100%
0.92526
Критический
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo