Vulnerability Details CVE-2022-2921
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-2921
-
cpe:2.3:a:notrinos:notrinoserp:0.1
-
cpe:2.3:a:notrinos:notrinoserp:0.2
-
cpe:2.3:a:notrinos:notrinoserp:0.3
-
cpe:2.3:a:notrinos:notrinoserp:0.4
-
cpe:2.3:a:notrinos:notrinoserp:0.5
-
cpe:2.3:a:notrinos:notrinoserp:0.6