9.8
CVSSv3

CVE-2022-24449

Published: 28/04/2022 Updated: 08/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Solar appScreener up to and including 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rt-solar solar appscreener

Github Repositories

Solar Appscreener XXE

CVE-2022-24449 Solar Appscreener XXE [Suggested description] An issue was found in Solar AppScreener SAST tool through 3104 An unauthorized actor, may exploit effected hosts where vulnerable version is installed, by uploading specially crafted XML files on hosts, which has an expired or non-installed license The lowest approved impact is XXE-SSRF [Additional Information] F