Record summary

CVE-2022-29775 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALiSpy 7.2.2.0 - Authentication BypassCVSS 9.8

iSpy 7.2.2.0 contains an authentication bypass vulnerability. An attacker can craft a URL and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the system.

Remediation

Upgrade to the latest version of iSpy (7.2.2.1 or higher) which includes a fix for the authentication bypass vulnerability.

WeaknessesCWE-287
Authorsarafatansari
Template tagscvecve2022ispyauth-bypassispyconnectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:ispyconnect:ispy:7.2.2.0:*:*:*:*:*:*:*
Shodan: http.html:"iSpy is running"
Shodan: http.html:"ispy is running"
FOFA: body="ispy is running"

Source: ProjectDiscovery

References

3