Vulnerability Details CVE-2022-45326
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.9%
CVSS Severity
CVSS v3 Score 4.9
Products affected by CVE-2022-45326
-
cpe:2.3:a:kwoksys:information_server:2.8.3
-
cpe:2.3:a:kwoksys:information_server:2.8.4
-
cpe:2.3:a:kwoksys:information_server:2.8.5
-
cpe:2.3:a:kwoksys:information_server:2.9.5