CVE-2022-45326

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
06/12/2022
Last modified:
23/04/2025

Description

An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kwoksys:information_server:*:*:*:*:*:*:*:* 2.9.5 (excluding)
cpe:2.3:a:kwoksys:information_server:2.9.5:sp23:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp25:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp26:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp29:*:*:*:*:*:*
cpe:2.3:a:kwoksys:information_server:2.9.5:sp30:*:*:*:*:*:*