gist.github.com
https://gist.github.com/securylight/79f673aa3a453c80c0e78f356a8f650b CVE-2022-29775
CRITICALNuclei
iSpy 7.2.2.0 - Authentication Bypass
Record summary
CVE-2022-29775 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALiSpy 7.2.2.0 - Authentication BypassCVSS 9.8
iSpy 7.2.2.0 contains an authentication bypass vulnerability. An attacker can craft a URL and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the system.
Remediation
Upgrade to the latest version of iSpy (7.2.2.1 or higher) which includes a fix for the authentication bypass vulnerability.
WeaknessesCWE-287
Authorsarafatansari
Template tagscvecve2022ispyauth-bypassispyconnectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ispyconnect:ispy:7.2.2.0:*:*:*:*:*:*:*
Shodan: http.html:"iSpy is running"
Shodan: http.html:"ispy is running"
FOFA: body="ispy is running"
https://gist.github.com/securylight/79f673aa3a453c80c0e78f356a8f650b https://github.com/securylight/CVES_write_ups/blob/main/iSpy_connect.pdf https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-29775 https://nvd.nist.gov/vuln/detail/CVE-2022-29775 https://github.com/securylight/CVES_write_ups
Source: ProjectDiscovery
References
3github.com
https://github.com/securylight/CVES_write_ups nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-29775