Vulnerability Description
OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email address, role(s), user type, license type, and personal details such as first name, last name, gender, and user preferences.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ovaledge | Ovaledge | <= 5.2.8 |
Related Weaknesses (CWE)
References
- https://cve.offsecguy.com/ovaledge/vulnerabilities/sensitive-data-exposure#cve-2ExploitThird Party Advisory
FAQ
What is CVE-2022-30359?
CVE-2022-30359 is a vulnerability with a CVSS score of 4.3 (MEDIUM). OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the...
How severe is CVE-2022-30359?
CVE-2022-30359 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30359?
Check the references section above for vendor advisories and patch information. Affected products include: Ovaledge Ovaledge.