CVE-2022-23904
Summary
| CVE | CVE-2022-23904 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-02 12:16:00 UTC |
| Updated | 2022-05-10 16:07:00 UTC |
| Description | Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rainworx | Auctionworx | All | All | All | All |
| Application | Rainworx | Auctionworx | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Online Auction Software - Create an Auction Website | RainWorx Software | MISC | www.rainworx.com | |
| Account Privilege upgrade on Auctionworx software (CVE-2022-23904) – Ebere | MISC | ebereorisi.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.