Vulnerabilities > CVE-2022-3826 - Incorrect Privilege Assignment vulnerability in Huaxiaerp Huaxia ERP

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
huaxiaerp
CWE-266

Summary

A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file /depotHead/list of the component Retail Management. The manipulation of the argument search leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212793 was assigned to this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Huaxiaerp
1

Common Weakness Enumeration (CWE)