CVSS v3
8.8
HIGH
EPSS Score
20.6 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.
Technical details
- Published
- 2023-05-02
- Exploit-DB
- EDB-51426
Frequently asked questions
What is CVE-2022-47878?
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.
Is CVE-2022-47878 actively exploited?
Active exploitation of CVE-2022-47878 has not been confirmed. The EPSS score is 20.6%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2022-47878?
CVE-2022-47878 has a CVSS v3 base score of 8.8 (HIGH severity).
Is CVE-2022-47878 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2022 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).