CVE-2022-23347High· 7.5▾ MidnightPoC availableBigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 2.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
13%
13% → 14%
Nuclei ×1
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
bigant_server = 5.6.06Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-23348Medium· 5.3BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
CVE-2022-26281High· 7.5BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
CVE-2022-23352High· 7.5An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
CVE-2022-23350Medium· 5.4BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-23349High· 8.8BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-23346High· 8.8BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.