CVE-2022-43712
Last modified
CVE-2022-43712 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass other security filters they are able to post unauthorized data to the server because of CVE-2022-22965.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass other security filters they are able to post unauthorized data to the server because of CVE-2022-22965.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gxsoftware | Xperiencentral | <= 10.36.0 |
References
- https://service.gxsoftware.com/hc/nl/articles/12208173122461Vendor Advisory
- https://service.gxsoftware.com/hc/nl/articles/12208173122461Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-43712?
How severe is CVE-2022-43712?
How do I fix CVE-2022-43712?
Are you affected by CVE-2022-43712?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
