CVE-2022-50992

Lỗ hổng CVE-2022-50992 là gì?

Dữ liệu gốc

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-12-14 (UTC).

Xác minh để tiếp tục phân tích

Bước xác minh ngắn giúp bảo vệ nguồn lỗ hổng và hạn chế việc gọi AI tự động.

Giới thiệu chung

Dữ liệu gốc

Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying file paths to the WorkflowService.getAttachment and WorkflowService.LoadTemplateProp methods. Attackers can exploit these methods without authentication to retrieve sensitive files including system configuration files and database credentials from the server. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-12-14 (UTC).

Sản phẩm và phạm vi ảnh hưởng

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Chi tiết kỹ thuật

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Khả năng khai thác

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Tác động kỹ thuật

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Tác động đến tổ chức

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Cách khắc phục

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.

Cách phát hiện

CyStack đang phân tích dữ liệu của lỗ hổng này. Nội dung sẽ tự động cập nhật khi hoàn tất.
Nguồn (6)
Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan
CyStack VulnScan dashboard