CVE Feed

    Dashboard / CVE / CVE-2022-26159

    CVE-2022-26159

    The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as plugins/web/service/search/auto-completion/<domain>/en.xml (and similar pathnames for other languages), which contain all characters typed by all users, including the content of private pages. For example, a private page may contain usernames, e-mail addresses, and possibly passwords.

    Published:Feb 28, 2022
    Last Modified:Nov 21, 2024
    EPS:Feb 28, 2022
    EPSS Score:0.9158
    CVSS Score:5.3

    Affected Products

    Vendor
    Ametys
    Product
    Ametys

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High