7.5
CVSSv3

CVE-2022-47879

Published: 12/05/2023 Updated: 24/05/2023
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jedox jedox 2020.2.5

jedox jedox cloud -

Exploits

Jedox version 202242 has a vulnerability in /be/rpcphp and /be/erpcphp that allows remote authenticated users to load arbitrary PHP classes from the rtn directory and to execute its methods ...
Jedox version 202025 suffers from having improper access controls in /tc/rpc that allows remote authenticated users to view details of database connections via the class comjedoxetlmngrConnections and the method getGlobalConnection ...