CVE-2022-22828
HIGHSynaman < 5.0 - Unauthenticated Unshared File Access via Base64-Encoded Filename
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-22828. PoCs published by videnlabs.
AI-analyzed exploit summary This repository documents an Insecure Direct Object Reference (IDOR) vulnerability in Synametrics SynaMan version 4.9 and earlier. The vulnerability allows unauthorized access to files in a user's home folder by manipulating a base64-encoded filename parameter in a GET request.
Description
An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
Exploits (1)
This repository documents an Insecure Direct Object Reference (IDOR) vulnerability in Synametrics SynaMan version 4.9 and earlier. The vulnerability allows unauthorized access to files in a user's home folder by manipulating a base64-encoded filename parameter in a GET request.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N