CVE-2023-22232

MEDIUM NUCLEI

Adobe Connect <11.4.5, 12.1.5 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-22232. PoCs published by h4shur. A Nuclei detection template is also available.

AI-analyzed exploit summary The provided content is a detailed writeup describing an Improper Access Control vulnerability (CVE-2023-22232) in Adobe Connect versions 11.4.5 and earlier, and 12.1.5 and earlier. It explains how an attacker can exploit the vulnerability to perform Local File Disclosure (LFD) by manipulating URL parameters to download arbitrary files from the server.

Description

Adobe Connect versions 11.4.5 (and earlier), 12.1.5 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the integrity of a minor feature. Exploitation of this issue does not require user interaction.

Exploits (2)

exploitdb WRITEUP
by h4shur · textwebappsmultiple
https://www.exploit-db.com/exploits/51327

The provided content is a detailed writeup describing an Improper Access Control vulnerability (CVE-2023-22232) in Adobe Connect versions 11.4.5 and earlier, and 12.1.5 and earlier. It explains how an attacker can exploit the vulnerability to perform Local File Disclosure (LFD) by manipulating URL parameters to download arbitrary files from the server.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Adobe Connect 11.4.5 and earlier, 12.1.5 and earlier
No auth needed
Prerequisites: Access to the target Adobe Connect instance · Knowledge of file paths on the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
by h4shur · textwebappsmultiple
https://www.exploit-db.com/exploits/49550

This exploit describes an information disclosure vulnerability in Adobe Connect 10 and earlier versions, where accessing specific endpoints reveals usernames or admin panel access without authentication.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Adobe Connect 10 and earlier
No auth needed
Prerequisites: knowledge of the target domain
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Adobe Connect < 12.1.5 - Local File Disclosure
MEDIUMVERIFIEDby 0xr2r
Shodan: title:"Adobe Connect" || http.title:"openvpn connect"
FOFA: title="openvpn connect"

Scores

CVSS v3 5.3
EPSS 0.8187
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
adobe/connect 11.0 - 11.4.5
Published Feb 17, 2023
Tracked Since Feb 18, 2026