Lucene search

K
cve[email protected]CVE-2022-42197
HistoryOct 20, 2022 - 1:15 p.m.

CVE-2022-42197

2022-10-2013:15:10
CWE-425
web.nvd.nist.gov
19
10
cve-2022-42197
nvd
user list function
access control
security vulnerability

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

24.8%

In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privileged users to modify user permissions to higher privileges.

Affected configurations

NVD
Node
simple_exam_reviewer_management_system_projectsimple_exam_reviewer_management_systemMatch1.0

Social References

More

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

0.001 Low

EPSS

Percentile

24.8%

Related for CVE-2022-42197