CVE-2022-28365
MEDIUM EXPLOITED NUCLEIReprise License Manager 14.2 - Info Disclosure
Title source: llmExploitation Summary
CVE-2022-28365 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.
Description
Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminfo. No authentication is required. The information disclosed is associated with software versions, process IDs, network configuration, hostname(s), system architecture, and file/directory details.
Nuclei Templates (1)
Reprise License Manager 14.2 - Information Disclosure
MEDIUMby Akincibor
Shodan:
http.html:"reprise license" || http.html:"reprise license manager"
FOFA:
body="reprise license manager" || body="reprise license"
References (4)
Core 4
Core References
Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/166647/Reprise-License-Manager-14.2-Cross-Site-Scripting-Information-Disclosure.html
Exploit, Mailing List, Third Party Advisory
https://seclists.org/fulldisclosure/2022/Apr/1
Broken Link
https://www.reprisesoftware.com/RELEASE_NOTES
Scores
CVSS v3
5.3
EPSS
0.0799
EPSS Percentile
94.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
VulnCheck KEV
2025-06-05
CWE
CWE-425
Status
published
Products (1)
reprisesoftware/reprise_license_manager
14.2 - 15.1
Published
Apr 09, 2022
Tracked Since
Feb 18, 2026