Vulnerability CVE-2022-45326


Published: 2022-12-06

Description:
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.

 References:
https://www.navsec.net/2022/11/12/kwoksys-xxe.html
http://www.kwoksys.com/wiki/index.php?title=Release_Notes

Copyright 2026, cxsecurity.com

 

Back to Top