{"api_version":"1","generated_at":"2026-07-23T11:10:28+00:00","cve":"CVE-2022-23904","urls":{"html":"https://cve.report/CVE-2022-23904","api":"https://cve.report/api/cve/CVE-2022-23904.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-23904","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-23904"},"summary":{"title":"CVE-2022-23904","description":"Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-05-02 12:16:00","updated_at":"2022-05-10 16:07:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"https://www.rainworx.com/","name":"https://www.rainworx.com/","refsource":"MISC","tags":[],"title":"Online Auction Software - Create an Auction Website | RainWorx Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/","name":"https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/","refsource":"MISC","tags":[],"title":"Account Privilege upgrade on Auctionworx software (CVE-2022-23904) – Ebere","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-23904","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23904","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"23904","vulnerable":"1","versionEndIncluding":"3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rainworx","cpe5":"auctionworx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"23904","vulnerable":"1","versionEndIncluding":"3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rainworx","cpe5":"auctionworx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"events","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-23904","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx: Events Edition."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.rainworx.com/","refsource":"MISC","name":"https://www.rainworx.com/"},{"refsource":"MISC","name":"https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/","url":"https://ebereorisi.com/blog/account-privilege-upgrade-on-auctionworx-software-cve-2022-23904/"}]}},"nvd":{"publishedDate":"2022-05-02 12:16:00","lastModifiedDate":"2022-05-10 16:07:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8,"baseSeverity":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6},"severity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:rainworx:auctionworx:*:*:*:*:events:*:*:*","versionEndIncluding":"3.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:rainworx:auctionworx:*:*:*:*:enterprise:*:*:*","versionEndIncluding":"3.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"23904","Ordinal":"226953","Title":"CVE-2022-23904","CVE":"CVE-2022-23904","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"23904","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}