Exploitation Summary
EIP tracks 2 public exploits for CVE-2022-22916. PoCs published by 0x7eTeam.
AI-analyzed exploit summary This repository provides a proof-of-concept for CVE-2022-22916, an RCE vulnerability in O2OA v6.4.7. The exploit involves authenticating as 'xadmin/o2', then creating and executing a malicious interface via the '/x_program_center/jaxrs/invoke' endpoint to achieve remote code execution.
Description
O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
Exploits (2)
This repository provides a proof-of-concept for CVE-2022-22916, an RCE vulnerability in O2OA v6.4.7. The exploit involves authenticating as 'xadmin/o2', then creating and executing a malicious interface via the '/x_program_center/jaxrs/invoke' endpoint to achieve remote code execution.
The repository provides a detailed technical writeup for CVE-2022-22916, an RCE vulnerability in O2OA v6.4.7. It includes step-by-step instructions, HTTP request templates, and payload examples for exploiting the vulnerability via the `/x_program_center/jaxrs/invoke` endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H