Lucene search

K
cvelistHYPRCVELIST:CVE-2022-2192
HistoryJul 19, 2022 - 2:07 p.m.

CVE-2022-2192

2022-07-1914:07:38
CWE-425
HYPR
www.cve.org
1
forced browsing
hypr server
privilege elevation
path tampering

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

65.6%

Forced Browsing vulnerability in HYPR Server version 6.10 to 6.15.1 allows remote attackers with a valid one-time recovery token to elevate privileges via path tampering in the Magic Link page. This issue affects: HYPR Server versions later than 6.10; version 6.15.1 and prior versions.

CNA Affected

[
  {
    "product": "HYPR Server",
    "vendor": "HYPR",
    "versions": [
      {
        "lessThan": "unspecified",
        "status": "affected",
        "version": "next of 6.10",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "6.15.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.003

Percentile

65.6%

Related for CVELIST:CVE-2022-2192