CVE-2022-30359

MEDIUM

OvalEdge < 5.2.8 - Authenticated Sensitive Data Exposure via /user/getUserList

Title source: llm
STIX 2.1

Description

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email address, role(s), user type, license type, and personal details such as first name, last name, gender, and user preferences.

References (1)

Core 1

Scores

CVSS v3 4.3
EPSS 0.0027
EPSS Percentile 18.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-922
Status published
Products (1)
ovaledge/ovaledge < 5.2.8
Published Oct 25, 2024
Tracked Since Feb 18, 2026