CVE-2022-29597

MEDIUM

Solutions Atlantic Regulatory Reporting System v500 - Authenticated Local File Inclusion via ShowDocument.aspx

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-29597. PoCs published by TheGetch.

AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2022-29597, a Local File Inclusion (LFI) vulnerability in Solutions Atlantic's RRS v500. The exploit demonstrates how an authenticated user can read arbitrary files by manipulating the `fileName` parameter in a GET request to `/RRSWeb/maint/ShowDocument/ShowDocument.aspx`.

Description

Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of the internal system file requested. This ability could allow for adversaries to extract sensitive data and/or files from the underlying file system, gain knowledge about the internal workings of the system, or access source code of the application.

Exploits (1)

nomisec WORKING POC
by TheGetch · poc
https://github.com/TheGetch/CVE-2022-29597

This repository contains a proof-of-concept for CVE-2022-29597, a Local File Inclusion (LFI) vulnerability in Solutions Atlantic's RRS v500. The exploit demonstrates how an authenticated user can read arbitrary files by manipulating the `fileName` parameter in a GET request to `/RRSWeb/maint/ShowDocument/ShowDocument.aspx`.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Solutions Atlantic RRS v500
Auth required
Prerequisites: Authenticated access to the RRS application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Product x_refsource_misc
https://solutions-atlantic.com/rrs/
Exploit, Third Party Advisory x_refsource_misc
https://github.com/TheGetch/CVE-2022-29597

Scores

CVSS v3 6.5
EPSS 0.0185
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
solutions-atlantic/regulatory_reporting_system 500
Published Jun 02, 2022
Tracked Since Feb 18, 2026