CVE-2022-23348Medium· 5.3▾ TwilightPoC availableBigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.7 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.4%
Nuclei ×1
BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
bigant_server = 5.6.06Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-23347High· 7.5BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
CVE-2022-26281High· 7.5BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.
CVE-2022-23352High· 7.5An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
CVE-2022-23350Medium· 5.4BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-23349High· 8.8BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-23346High· 8.8BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.