CVE-2022-47075 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 59.4% (pctl 99)
Patch early
A public exploit exists.
Description
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 59.41% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-02-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| smartofficepayroll | smartoffice |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated) | 2023-06-22 |
References
- http://packetstormsecurity.com/files/173093/Smart-Office-Web-20.28-Information-Disclosure-Insecure-Direct-Object-Reference.html
- https://cvewalkthrough.com/smart-office-suite-cve-2022-47076-cve-2022-47075/
- https://cvewalkthrough.com/smart-office-suite-unauthenticated-data-ex/
- https://youtu.be/D42upepxzwM
- http://packetstormsecurity.com/files/173093/Smart-Office-Web-20.28-Information-Disclosure-Insecure-Direct-Object-Reference.html
- https://cvewalkthrough.com/smart-office-suite-cve-2022-47076-cve-2022-47075/
- https://cvewalkthrough.com/smart-office-suite-unauthenticated-data-ex/
- https://youtu.be/D42upepxzwM
→ the Explorer · watch your stack · NVD