2024-12-08 03:06:42 +00:00

89 lines
2.6 KiB
JSON

{
"id": "CVE-2022-44786",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-11-21T23:15:13.350",
"lastModified": "2024-11-21T07:28:26.960",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do POST and GET requests to each application."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en Appalti & Contratti 9.12.2. Las aplicaciones web de destino permiten la Inclusi\u00f3n de Archivos Locales en cualquier p\u00e1gina bas\u00e1ndose en el par\u00e1metro href para especificar la p\u00e1gina JSP que se va a representar. Esto afecta las solicitudes POST y GET de ApriPagina.do para cada aplicaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:maggioli:appalti_\\&_contratti:9.12.2:*:*:*:*:*:*:*",
"matchCriteriaId": "CDE25FE7-3242-4542-A150-D24ED7156CD2"
}
]
}
]
}
],
"references": [
{
"url": "https://members.backbox.org/maggioli-appalti-contratti-multiple-vulnerabilities/",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://members.backbox.org/maggioli-appalti-contratti-multiple-vulnerabilities/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}