NA

CVE-2022-47075

Published: 28/02/2023 Updated: 23/06/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in Smart Office Web 20.28 and previous versions allows malicious users to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

smartofficepayroll smartoffice

Vendor Advisories

Check Point Reference: CPAI-2022-1986 Date Published: 15 Jan 2024 Severity: High ...

Exploits

# Exploit Title: Smart Office Web 2028 - Remote Information Disclosure (Unauthenticated) # Shodan Dork:: inurl:"wwwshodanio/search?query=smart+office" # Date: 09/Dec/2022 # Exploit Author: Tejas Nitin Pingulkar (cvewalkthroughcom/) # Vendor Homepage: smartofficepayrollcom/ # Software Link: smartofficepayrollcom ...
Smart Office Web version 2028 suffers from information disclosure due to an insecure direct object reference vulnerability ...