CVE-2022-23766

HIGH

BigFileAgent < 1.0.1.9 - Arbitrary File Execution via Improper Input Validation

Title source: llm
STIX 2.1

Description

An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a general website.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0048
EPSS Percentile 37.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
bigfile/bigfileagent < 1.0.1.9
Published Sep 19, 2022
Tracked Since Feb 18, 2026