{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-47075/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-47075/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-47075/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-47075/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-47075/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-47075"},"sightings":{"href":"/api/v1/sightings/cve-2022-47075"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.59407,"kev":false,"percentile":0.99079},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-47075.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2022-47075\n\ninfo:\n  name: Smart Office Web 20.28 - Information Disclosure\n  author: r3Y3r53\n  severity: high\n  description: |\n    An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.\n  impact: |\n    Unauthenticated attackers can download sensitive employee information including personal details, employee codes, and reporting relationships through vulnerable export endpoints in Smart Office Web, potentially exposing confidential HR data.\n  remediation: |\n    Upgrade to a version of Smart Office Web later than 20.28 that implements proper authentication checks on export endpoints.\n  reference:\n    - https://packetstormsecurity.com/files/173093/Smart-Office-Web-20.28-Information-Disclosure-Insecure-Direct-Object-Reference.html\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-47075\n    - http://packetstormsecurity.com/files/173093/Smart-Office-Web-20.28-Information-Disclosure-Insecure-Direct-Object-Reference.html\n    - https://cvewalkthrough.com/smart-office-suite-unauthenticated-data-ex/\n    - https://youtu.be/D42upepxzwM\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2022-47075\n    epss-score: 0.59407\n    epss-percentile: 0.99078\n    cpe: cpe:2.3:a:smartofficepayroll:smartoffice:*:*:*:*:web:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: smartofficepayroll\n    product: smartoffice\n  tags: cve,cve2022,packetstorm,smart-office,info,exposure,smartofficepayroll,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/ExportReportingManager.aspx\"\n\n    matchers:\n      - type: dsl\n        dsl:\n          - 'status_code == 200'\n          - 'contains(content_type, \"application/CSV\")'\n          - 'contains(body, \"EmployeeName\") && contains(body, \"EmployeeCode\")'\n        condition: and\n# digest: 4b0a00483046022100d58231b453fe0a8acda405e7904dcbb295499bd28f6baee79074b43aebf8c62f022100ed57e62f298d60da76ce01c49511eb137cb640eb1bd1b64dbd7306cced8e49ca:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2022-47075"}