CVE-2022-26159 Information

Description

The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion//en.xml (and similar pathnames for other languages) which contain all characters typed by all users including the content of private pages. For example a private page may contain usernames e-mail addresses and possibly passwords.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Reference

https://issues.ametys.org/browse/CMS-10973 https://podalirius.net/en/cves/2022-26159/ https://github.com/p0dalirius/CVE-2022-26159-Ametys-Autocompletion-XML/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

5.3

Share on: