Sploitus

CVE-2022-25237

1 known exploit for CVE-2022-25237

Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access privileged API endpoints. This can lead to remote code execution by abusing the privileged API actions.

Affected products
Bonita Web
Bonitasoft Bonita Web
= 2021.2
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
56.7% (99th percentile)
NVD status
Modified
Published
2022-05-27
CVE-2022-25237 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-25237

Proof-of-concept code and exploit modules indexed by Sploitus