peter bassill · operator
$ cve CVE-2022-47879 JSON

CVE-2022-47879 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 6.3% (pctl 93)

Patch early

A public exploit exists.

Description

A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version 22.5 or earlier. The issue was resolved with version 23.2 and later versions are not affected.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS6.3% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2023-05-12
Last modified2026-07-09

Affected (2)

VendorProduct
jedoxjedox
jedoxjedox cloud

Public exploits

SourceTitleDate
exploit-dbJedox 2022.4.2 - Code Execution via RPC Interfaces2023-05-05

References

→ the Explorer  ·  watch your stack  ·  NVD