CVE-2022-23055
Title: Missing Authorization in chat rooms functionality
Missing Authorization, Impersonation, Information Disclosure
Proof Of Concept
No public PoC currently indexed for CVE-2022-23055.
CWE Category
CWE-862
Published Date
Jun 22, 2022
Modified Date
Nov 21, 2024
Exploit Status
Not Found
Score
5.5
CVSS v2.0
Exploit Probability (EPSS)
1.14%
Vulnerability Summary
CVE-2022-23055: In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionality. A low privileged attacker can send a direct message or a group message to any member or group, impersonating themselves as the administrator. The attacker can also read chat messages of groups that they do not belong to, and of other users.
Impacted Vendors
Reference Links
https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134
https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155
https://www.mend.io/vulnerability-database/CVE-2022-23055
https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L134
https://github.com/frappe/frappe/blob/v13.0.2/frappe/chat/doctype/chat_message/chat_message.py#L155
https://www.mend.io/vulnerability-database/CVE-2022-23055
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
5.5
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:S/C:P/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2022-23055 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:S/C:P/I:P/A:N
Affected Stack
No specific products linked.