Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of decoy users via a crafted GET request sent to /WebApp/DeceptionUser/GetAllDeceptionUsers.
References
| Link | Resource |
|---|---|
| https://www.cynet.com/platform/ | Vendor Advisory |
| https://www.srlabs.de/bites/edr-security | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-09-08 16:15
Updated : 2023-08-08 14:21
NVD link : CVE-2022-27969
Mitre link : CVE-2022-27969
JSON object : View
Products Affected
cynet
- cynet_360
CWE
