9.8
CVSSv3

CVE-2022-22832

Published: 06/02/2022 Updated: 08/08/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 892
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

servisnet tessa 0.0.2

Exploits

This Metasploit module exploits privilege escalation in Servisnet Tessa triggered by the add new sysadmin user flow with any user authorization An API request to "/data-service/users/[userid]" with any low-authority user returns other users' information in response The encrypted password information is included here, but privilege escalation is a ...