CVE-2022-32272
CRITICALOPSWAT MetaDefender Core < 5.1.2 - Privilege Escalation via Incorrect Access Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-32272. PoCs published by Ulascan Yildirim.
AI-analyzed exploit summary This PoC exploits a privilege escalation vulnerability in OPSWAT Metadefender Core by manipulating the OMS_CSRF_TOKEN to elevate user roles to admin. It requires valid credentials and interacts with the API to modify user roles.
Description
OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.
Exploits (1)
This PoC exploits a privilege escalation vulnerability in OPSWAT Metadefender Core by manipulating the OMS_CSRF_TOKEN to elevate user roles to admin. It requires valid credentials and interacts with the API to modify user roles.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H