CVE-2022-22798 Information
Jun 07, 2022
cve
Description
Sysaid – Pro Plus Edition SysAid Help Desk Broken Access Control v20.4.74 b10 v22.1.20 b62 v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or EndUserPortal.JSP then he needs to change the path in the URL to /ConcurrentLogin%2ejsp after that he will receive an error message with a login button by clicking on it he will connect to the system dashboard. The attacker can receive sensitive data like server details usernames workstations etc. He can also perform actions such as uploading files deleting calls from the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.gov.il/en/departments/faq/cve_advisories
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: