First published: Thu May 12 2022(Updated: )
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame and File/URL : [here is the LFI] Solution: Update to 22.2.20 cloud version, or to 22.1.64 on premise version.
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid On-Premises | <22.1.64 | |
Sysaid On-Premises | <22.2.20 |
Update to 22.2.20 cloud version, or to 22.1.64 on premise version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23166 is a vulnerability that allows an unauthenticated attacker to access the Sysaid system through a local file inclusion (LFI) attack.
CVE-2022-23166 has a severity rating of 9.8, which is classified as critical.
Sysaid versions up to 22.1.64 (on-premises) and up to 22.2.20 (cloud) are affected by CVE-2022-23166.
To fix CVE-2022-23166, update to version 22.2.20 of the cloud version or apply the relevant security patch provided by Sysaid.
You can find more information about CVE-2022-23166 at the following link: [here is the LFI]