CVE-2025-22492
MEDIUMForeseer Reporting Software <1.5.100 - Info Disclosure
Title source: llmDescription
The connection string visible to users with access to FRSCore database on Foreseer Reporting Software (FRS) VM, this string can be used for gaining administrative access to the 4crXref database. This vulnerability has been resolved in the latest version 1.5.100 of FRS.
Scores
CVSS v3
6.3
EPSS
0.0003
EPSS Percentile
8.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-922
Status
published
Products (1)
Eaton/Foreseer Reporting Software (FRS)
< 1.5.100
Published
Feb 28, 2025
Tracked Since
Feb 18, 2026