Lucene search

K
cveVulDBCVE-2022-3826
HistoryNov 02, 2022 - 1:15 p.m.

CVE-2022-3826

2022-11-0213:15:18
CWE-266
VulDB
web.nvd.nist.gov
27
cve-2022-3826
huaxia erp
vulnerability
remote attack
information disclosure
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

30.4%

A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file /depotHead/list of the component Retail Management. The manipulation of the argument search leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212793 was assigned to this vulnerability.

Affected configurations

Nvd
Node
huaxiaerphuaxia_erpMatch-
VendorProductVersionCPE
huaxiaerphuaxia_erp-cpe:2.3:a:huaxiaerp:huaxia_erp:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Huaxia",
    "product": "ERP",
    "versions": [
      {
        "version": "n/a",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.3

Confidence

High

EPSS

0.001

Percentile

30.4%

Related for CVE-2022-3826