An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.
References
Link Resource
https://github.com/videnlabs/CVE-2022-22828/ Exploit Third Party Advisory
https://web.synametrics.com/SynamanVersionHistory.htm Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-01-27T05:41:02

Updated: 2022-01-27T05:41:02

Reserved: 2022-01-08T00:00:00


Link: CVE-2022-22828

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-27T06:15:07.777

Modified: 2022-02-02T16:12:19.477


Link: CVE-2022-22828

JSON object: View

cve-icon Redhat Information

No data.

CWE