VulnerabilityModified
CVE-2022-23320
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries.
HIGH 7.5EPSS 1.64%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- xerox/xmpie ustore
- Source
- cve@mitre.org
References
- https://www.linkedin.com/feed/update/urn:li:activity:6894666176450887681?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A6894666176450887681%2C6895051709354192896%29Third Party Advisory
- https://www.triaxiomsecurity.com/xmpie-ustore-vulnerabilities-discovered/Exploit, Third Party Advisory
- https://www.xmpie.com/ustore-release-notes/Release Notes, Vendor Advisory
- https://www.linkedin.com/feed/update/urn:li:activity:6894666176450887681?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A6894666176450887681%2C6895051709354192896%29Third Party Advisory
- https://www.triaxiomsecurity.com/xmpie-ustore-vulnerabilities-discovered/Exploit, Third Party Advisory
- https://www.xmpie.com/ustore-release-notes/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.