CVE-2022-26111
Summary
| CVE | CVE-2022-26111 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-25 15:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the IRISNext application user, running on the web server. |
Risk And Classification
Problem Types: CWE-917
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-Advisory/CVE-2022-26111.pdf at main · post-cyberlabs/CVE-Advisory · GitHub | MISC | github.com | |
| IRISNEXT By I.R.I.S. group | MISC | varsnext.iriscorporate.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.