CVE-2022-45326

An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
References
Configurations

Configuration 1

cpe:2.3:a:kwoksys:information_server:2.9.5:sp25:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp26:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp29:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp30:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:*:*:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp23:*:*:*:*:*:*

Information

Published : 2022-12-06 05:15

Updated : 2022-12-08 04:34


NVD link : CVE-2022-45326

Mitre link : CVE-2022-45326

Products Affected
No products.
CWE
CWE-611

Improper Restriction of XML External Entity Reference