CVE-2022-47880
MEDIUMJedox 2020.2.5 - Authenticated Information Disclosure via Test Connection Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-47880. PoCs published by Team Syslifters.
AI-analyzed exploit summary This exploit describes an information disclosure vulnerability in Jedox 2022.4.2 and older versions, where authenticated users can modify database connection details to capture cleartext credentials via a controlled server. The PoC involves intercepting network traffic during a connection test.
Description
An Information disclosure vulnerability in /be/rpc.php in Jedox GmbH Jedox 2020.2.5 allow remote, authenticated users with permissions to modify database connections to disclose a connections' cleartext password via the 'test connection' function.
Exploits (1)
This exploit describes an information disclosure vulnerability in Jedox 2022.4.2 and older versions, where authenticated users can modify database connection details to capture cleartext credentials via a controlled server. The PoC involves intercepting network traffic during a connection test.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N