CVE-2022-45183

HIGH

PowerShell Universal 2.0.0-2.12.5 - Privilege Escalation via App Token ID Retrieval

Title source: llm
STIX 2.1

Description

Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.

References (3)

Core 3
Core References
Release Notes, Vendor Advisory
https://docs.powershelluniversal.com/changelog
Vendor Advisory
https://ironmansoftware.com

Scores

CVSS v3 8.8
EPSS 0.0077
EPSS Percentile 50.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
ironmansoftware/powershell_universal 2.0.0 - 2.12.6
Published Nov 14, 2022
Tracked Since Feb 18, 2026