CVE Vulnerabilities

CVE-2022-47075

Published: Feb 28, 2023 | Modified: Jun 23, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

Affected Software

Name Vendor Start Version End Version
Smartoffice Smartofficepayroll * 20.28 (including)

References