jedox.com
http://jedox.com/ CVE-2022-47879
HIGH
Jedox 2022.4.2 - Code Execution via RPC Interfaces
Record summary
CVE-2022-47879 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version 22.5 or earlier. The issue was resolved with version 23.2 and later versions are not affected.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 24, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBJedox 2022.4.2 - Code Execution via RPC InterfacesExploitDB exploitby Team SysliftersNot analyzed1 file
References
7docs.syslifters.com
https://docs.syslifters.com/assets/vulnerability-disclosure/Vulnerability-Disclosure-Jedox-Jedox-04-2023.pdf jedox.mantishub.io
https://jedox.mantishub.io/app/issues/57236 jedox.mantishub.io
https://jedox.mantishub.io/app/issues/57237 jedox.mantishub.io
https://jedox.mantishub.io/app/issues/57238 jedox.mantishub.io
https://jedox.mantishub.io/app/issues/57239 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-47879