Vulnerability Details CVE-2022-30619
Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule. under the function : /AgilePointServer/Extension/FetchUsingEncodedData in the parameter: EncodedData
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.1%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 6.5
Products affected by CVE-2022-30619
-
cpe:2.3:a:agilepoint:agilepoint_nx:6.0
-
cpe:2.3:a:agilepoint:agilepoint_nx:7.0