MEDIUM
An issue was discovered in OverIT Geocall before version 8.0
Published Mar 7, 2022
6.5
MEDIUMCVSS 3.1
EPSS 14.50%
Description
An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exploit a XXE vulnerability to read arbitrary files from the filesystem.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27973 Advisory
- https://labs.yarix.com/2022/03/overit-framework-xslt-injection-and-xxe-cve-2022-22834-cve-2022-22835/ ExploitThird Party Advisory
- https://labs.yarix.com/advisories/cve-2022-22835/ Third Party Advisory
- https://overit.us/products/geocall/ ProductVendor Advisory
- https://www.overit.ai/product/nextgen-fsm/
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27973 | Advisory | |
| https://labs.yarix.com/2022/03/overit-framework-xslt-injection-and-xxe-cve-2022-22834-cve-2022-22835/ | ExploitThird Party Advisory | |
| https://labs.yarix.com/advisories/cve-2022-22835/ | Third Party Advisory | |
| https://overit.us/products/geocall/ | ProductVendor Advisory | |
| https://www.overit.ai/product/nextgen-fsm/ |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 7, 2022
Updated Sep 18, 2024
Reserved Jan 8, 2022
Link CVE-2022-22835
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-27973 Assigner mitre
Published Mar 7, 2022
Updated Sep 18, 2024
Exploited since n/a
Link EUVD-2022-27973