Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-25237

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.78
EPSS Ranking 98.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2022-25237


Contact Us

Shodan ® - All rights reserved