CVE-2022-4257

MEDIUM EXPLOITED IN THE WILD

C-DATA Web Management System - Argument Injection

Title source: llm
STIX 2.1

Description

A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-bin/jumpto.php of the component GET Parameter Handler. The manipulation of the argument hostname leads to argument injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214631.

Scores

CVSS v3 6.3
EPSS 0.0274
EPSS Percentile 86.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2023-02-15
InTheWild.io 2023-02-15
CWE
CWE-78 CWE-707
Status published
Products (1)
cdatatec/c-data_web_management_system
Published Dec 01, 2022
Tracked Since Feb 18, 2026