CVE-2022-23345High· 7.5▾ TwilightBigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.7%
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
bigant_server = 5.6.06Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-26281High· 7.5BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
CVE-2022-23352High· 7.5An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
CVE-2022-23350Medium· 5.4BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-23349High· 8.8BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-23348Medium· 5.3BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
CVE-2022-23347High· 7.5BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.