CVE-2022-45326: XEE
Published Dec 6, 2022
·Updated
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
Affected Software
6 affected components
Kwoksys Information Server<2.9.5
Kwoksys Information Server=2.9.5-sp23
Kwoksys Information Server=2.9.5-sp25
Kwoksys Information Server=2.9.5-sp26
Kwoksys Information Server=2.9.5-sp29
Kwoksys Information Server=2.9.5-sp30
Remediation
Patch Available
Event History
Dec 6, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45326?
CVE-2022-45326 is considered a moderate severity vulnerability due to the potential for server-side request forgery (SSRF) attacks.
2
How do I fix CVE-2022-45326?
To fix CVE-2022-45326, upgrade to Kwoksys Kwok Information Server version 2.9.5.SP31 or later.
3
Who is affected by CVE-2022-45326?
CVE-2022-45326 affects remote authenticated users of Kwokys Kwok Information Server versions prior to 2.9.5.SP31.
4
What type of vulnerability is CVE-2022-45326?
CVE-2022-45326 is an XML external entity (XXE) injection vulnerability.
5
Can CVE-2022-45326 lead to data breaches?
Yes, CVE-2022-45326 can potentially lead to sensitive data exposure through SSRF attacks.