CVE-2022-41876

HIGH

ezplatform-graphql <2.3.12, <1.0.13 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-41876. PoCs published by Skileau.

AI-analyzed exploit summary This PoC exploits CVE-2022-41876, an information disclosure vulnerability in eZ Platform, allowing unauthenticated users to retrieve password hashes and other sensitive user data via GraphQL introspection and path enumeration.

Description

ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and 1.0.13 are subject to Insecure Storage of Sensitive Information. Unauthenticated GraphQL queries for user accounts can expose password hashes of users that have created or modified content, typically administrators and editors. This issue has been patched in versions 2.3.12, and 1.0.13 on the 1.X branch. Users unable to upgrade can remove the "passwordHash" entry from "src/bundle/Resources/config/graphql/User.types.yaml" in the GraphQL package, and other properties like hash type, email, login if you prefer.

Exploits (1)

nomisec WORKING POC 7 stars
by Skileau · poc
https://github.com/Skileau/CVE-2022-41876

This PoC exploits CVE-2022-41876, an information disclosure vulnerability in eZ Platform, allowing unauthenticated users to retrieve password hashes and other sensitive user data via GraphQL introspection and path enumeration.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: eZ Platform (Ibexa)
No auth needed
Prerequisites: GraphQL endpoint accessible · Introspection enabled on the GraphQL endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0416
EPSS Percentile 89.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200 CWE-922
Status published
Products (3)
ezsystems/ezplatform-graphql 1.0.0-rc1 - 1.0.13Packagist
ibexa/ezplatform-graphql 2.0.0 beta1
ibexa/ezplatform-graphql 1.0.0 - 1.0.13
Published Nov 10, 2022
Tracked Since Feb 18, 2026