← Back

CVE-2022-30359

nvd nist
Published: Oct 25, 2024Modified: Oct 31, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email address, role(s), user type, license type, and personal details such as first name, last name, gender, and user preferences.

Affected (1)

Products: Ovaledge: Ovaledge
1 product
Ovaledge
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.2.8

References (1)

Timeline

No history available yet.