CVE-2022-46945
CRITICALNagVis < 1.9.34 - Arbitrary File Read via Hover URL Component
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-46945. PoCs published by xerosec.
AI-analyzed exploit summary This exploit leverages an arbitrary file read vulnerability in NagVis 1.9.33 via the `getHoverUrl` AJAX endpoint, allowing authenticated users to read local files using the `file://` protocol. The PoC includes authentication handling and JSON response parsing to display file contents.
Description
Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
Exploits (1)
This exploit leverages an arbitrary file read vulnerability in NagVis 1.9.33 via the `getHoverUrl` AJAX endpoint, allowing authenticated users to read local files using the `file://` protocol. The PoC includes authentication handling and JSON response parsing to display file contents.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L