Vulnerabilities > Kwoksys > Information Server > 2.8.5

DATE CVE VULNERABILITY TITLE RISK
2022-12-06 CVE-2022-45326 XXE vulnerability in Kwoksys Information Server
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
network
low complexity
kwoksys CWE-611
4.9