logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-46478

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-46478

Description:
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.
Last updated date:
01/23/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
01/23/2023
Reference url to background

https://github.com/WeiYe-Jing/datax-web/issues/587

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy