CVE-2022-45326
06.12.2022, 17:15
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.Enginsight
Vendor | Product | Version |
---|---|---|
kwoksys | information_server | 𝑥 < 2.9.5 |
kwoksys | information_server | 2.9.5:sp23 |
kwoksys | information_server | 2.9.5:sp25 |
kwoksys | information_server | 2.9.5:sp26 |
kwoksys | information_server | 2.9.5:sp29 |
kwoksys | information_server | 2.9.5:sp30 |
𝑥
= Vulnerable software versions