packetstormsecurity.com
http://packetstormsecurity.com/files/173093/Smart-Office-Web-20.28-Information-Disclosure-Insecure-Direct-Object-Reference.html CVE-2022-47076
HIGH
Smart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)
Record summary
CVE-2022-47076 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to view sensitive information via DisplayParallelLogData.aspx.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBSmart Office Web 20.28 - Remote Information Disclosure (Unauthenticated)ExploitDB exploitby Tejas PingulkarNot analyzed1 file
References
5cvewalkthrough.com
https://cvewalkthrough.com/smart-office-suite-cve-2022-47076-cve-2022-47075 cvewalkthrough.com
https://cvewalkthrough.com/smart-office-suite-unauthenticated-data-ex nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-47076 youtu.be
https://youtu.be/D42upepxzwM