CVE-2022-23904
Last modified
CVE-2022-23904 is a high-severity vulnerability rated 8/10 on the CVSS scale. Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rainworx | Auctionworx | <= 3.1 |
References
- https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/Exploit, Third Party Advisory
- https://www.rainworx.com/Vendor Advisory
- https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/Exploit, Third Party Advisory
- https://www.rainworx.com/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23904?
How severe is CVE-2022-23904?
How do I fix CVE-2022-23904?
Are you affected by CVE-2022-23904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
