Vulnerability Details CVE-2022-24449
Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 75.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-24449
-
cpe:2.3:a:rt-solar:solar_appscreener:-
-
cpe:2.3:a:rt-solar:solar_appscreener:3.10.4