8.8
CVSSv3

CVE-2022-47878

Published: 02/05/2023 Updated: 10/05/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jedox jedox 2020.2.5

Exploits

Jedox version 202025 suffers from a remote code execution vulnerability via the configurable storage path ...