Vulnerabilities > CVE-2022-40036 - Unspecified vulnerability in Blog-Ssm Project Blog-Ssm 1.0

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
blog-ssm-project

Summary

An issue was discovered in Rawchen blog-ssm v1.0 allows an attacker to obtain sensitive user information by bypassing permission checks via the /adminGetUserList component.

Vulnerable Configurations

Part Description Count
Application
Blog-Ssm_Project
1