CVE-2022-23904
Last modified
CVE-2022-23904 is a high-severity vulnerability rated 8/10 on the CVSS scale. Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rainworx | Auctionworx | <= 3.1 |
References
- https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/Exploit, Third Party Advisory
- https://www.rainworx.com/Vendor Advisory
- https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/Exploit, Third Party Advisory
- https://www.rainworx.com/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23904?
How severe is CVE-2022-23904?
How do I fix CVE-2022-23904?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-23899MCMS v5.2.5 was discovered to contain a SQL injection vulner…9.8
- CVE-2022-2390Apps developed with Google Play Services SDK incorrectly had…8.4
- CVE-2022-23900A command injection vulnerability in the API of the Wavlink …9.8
- CVE-2022-23901A stack overflow re2c 2.2 exists due to infinite recursion i…9.8
- CVE-2022-23902Tongda2000 v11.10 was discovered to contain a SQL injection …9.8
- CVE-2022-23903A Cross Site Scripting (XSS) vulnerability exists in pearadm…5.4
- CVE-2022-23906CMS Made Simple v2.2.15 was discovered to contain a Remote C…7.2
- CVE-2022-23907CMS Made Simple v2.2.15 was discovered to contain a reflecte…6.1
- CVE-2022-23909There is an unquoted service path in Sherpa Connector Servic…7.8
- CVE-2022-2391The Inspiro PRO WordPress plugin does not sanitize the portf…5.4
- CVE-2022-23911The Testimonial WordPress Plugin WordPress plugin before 1.4…7.2
- CVE-2022-23912The Testimonial WordPress Plugin WordPress plugin before 1.4…6.1
Are you affected by CVE-2022-23904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
