CyberRota
Live Feed
Back to database

CVE-2022-47878

HIGH · CVSS 8.8 EPSS 35.72% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published: 2023-05-02 · Last synced: 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-47878
Severity
HIGH
CVSS
8.8
EPSS
35.72%

Original NVD Description

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.