CVE-2022-47075
28.02.2023, 23:15
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.Enginsight
Vendor | Product | Version |
---|---|---|
smartofficepayroll | smartoffice | 𝑥 ≤ 20.28 |
𝑥
= Vulnerable software versions
References