Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-43712
HistoryJul 26, 2023 - 2:15 p.m.

Design/Logic Flaw

2023-07-2614:15:00
PRIOn knowledge base
www.prio-n.com
12
flaw
post requests
gx software xperiencentral
unauthorized user
security filters
server
cve-2022-22965
nvd

8.4 High

AI Score

Confidence

High

0.975 High

EPSS

Percentile

100.0%

POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass other security filters they are able to post unauthorized data to the server because of CVE-2022-22965.

CPENameOperatorVersion
xperiencentralle10.36.0