CVE-2022-34769
Last modified
CVE-2022-34769 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the value of the ptMsl parameter and then the attacker can access sensitive data that he not supposed to access because its belong to another user.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in order to achieve his goals is to change the value of the ptMsl parameter and then the attacker can access sensitive data that he not supposed to access because its belong to another user.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rashim | Michlol | < 187.4392 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34769?
How severe is CVE-2022-34769?
How do I fix CVE-2022-34769?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34762A CWE-22: Improper Limitation of a Pathname to a Restricted …7.5
- CVE-2022-34763A CWE-345: Insufficient Verification of Data Authenticity vu…7.5
- CVE-2022-34764A CWE-119: Improper Restriction of Operations within the Bou…7.5
- CVE-2022-34765A CWE-73: External Control of File Name or Path vulnerabilit…5.3
- CVE-2022-34767Web page which "wizardpwd.asp" ALLNET Router model WR0500AC …9.8
- CVE-2022-34768insert HTML / js code inside input how to get to the vulnera…7.5
- CVE-2022-3477The tagDiv Composer WordPress plugin before 3.5, required by…9.8
- CVE-2022-34770Tabit - sensitive information disclosure. Several APIs on th…7.5
- CVE-2022-34771Tabit - arbitrary SMS send on Tabits behalf. The resend OTP …3.5
- CVE-2022-34772Tabit - password enumeration. Description: Tabit - password …8.8
- CVE-2022-34773Tabit - HTTP Method manipulation. https://bridge.tabit.cloud…9.8
- CVE-2022-34774Tabit - Arbitrary account modification. One of the endpoints…5.3
Are you affected by CVE-2022-34769?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
