peter bassill · operator
$ cve CVE-2022-47075 JSON

CVE-2022-47075 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 59.4% (pctl 99)

Patch early

A public exploit exists.

Description

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS59.41% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2023-02-28
Last modified2026-06-17

Affected (1)

VendorProduct
smartofficepayrollsmartoffice

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD