CVE-2022-45326
MEDIUMKwoksys Information Server < 2.9.5.SP31 - Authenticated XML External Entity Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-45326. PoCs published by navsec.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2022-45326, an XXE vulnerability in KwokSys < v2.9.5.SP31, allowing authenticated users to read arbitrary files or conduct SSRF attacks via a crafted RSS feed. The exploit includes authentication, payload delivery via a local HTTP server, and file retrieval.
Description
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
Exploits (1)
The repository contains a functional exploit for CVE-2022-45326, an XXE vulnerability in KwokSys < v2.9.5.SP31, allowing authenticated users to read arbitrary files or conduct SSRF attacks via a crafted RSS feed. The exploit includes authentication, payload delivery via a local HTTP server, and file retrieval.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N