ZeroHour

CVE-2022-47075

PoC
CVSS 3.1
7.5 high
EPSS
59%p99
Published
()
Modified
Description

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

Vendors
smartofficepayroll
Products
smartoffice
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.