S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2022-47075 Scanner

CVE-2022-47075 scanner - Information Disclosure vulnerability in Smart Office Web

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-47075
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

An issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parameter to ExportEmployeeDetails.aspx, and to ExportReportingManager.aspx.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Smart Office Web is a comprehensive office management and payroll solution designed for businesses to manage their employee details, attendance, payroll, and other HR-related tasks efficiently online. The platform is tailored for HR departments and office administrators, facilitating a streamlined process for managing workforce data and payroll operations. It aims to enhance productivity and ensure compliance with labor laws through its automated features, making it a critical tool for modern businesses aiming to optimize their human resource management practices.

The information disclosure vulnerability in Smart Office Web version 20.28 and earlier allows attackers to exploit insufficient security controls to download sensitive employee information without authentication. This vulnerability is particularly alarming as it exposes confidential data, such as employee names, codes, and potentially other personal and financial details, through accessible endpoints like ExportEmployeeDetails.aspx and ExportReportingManager.aspx. This flaw undermines the confidentiality and integrity of the data managed by the Smart Office Web platform.

This security issue arises from an insecure direct object reference (IDOR) at specific endpoints, allowing unauthorized access to sensitive CSV files containing employee information. By manipulating the action name parameter in requests to these endpoints, attackers can bypass authentication mechanisms to retrieve files that should only be accessible to authenticated and authorized users. The vulnerability highlights a significant oversight in access control and data protection mechanisms, making it critical to address promptly to prevent potential data breaches.

The exploitation of this vulnerability can lead to unauthorized disclosure of sensitive employee information, including personal identifiers and possibly financial details. Such exposure may result in identity theft, financial fraud, and reputational damage to both employees and the organization. It also poses legal and compliance risks, as data protection regulations mandate strict controls over personal data handling and privacy.

By leveraging S4E's expertise in cyber threat exposure management, organizations can proactively identify and remediate vulnerabilities like the one found in Smart Office Web. Our platform provides detailed vulnerability assessments, enabling businesses to secure their digital infrastructure and protect sensitive information against unauthorized access. Joining S4E ensures that your organization stays ahead of cyber threats, maintaining the confidentiality, integrity, and availability of your data.

 

References

Solution Advice
  1. Immediately restrict access to the vulnerable endpoints and ensure that proper authentication and authorization checks are in place before accessing sensitive information.
  2. Upgrade to the latest version of Smart Office Web that addresses this vulnerability or apply available patches.
  3. Conduct a comprehensive security review of all web application endpoints to identify and fix potential vulnerabilities that could lead to unauthorized information disclosure.
  4. Implement robust access control measures and regularly audit access logs to detect and respond to unauthorized access attempts promptly.
  5. Provide training to developers and administrators on secure coding practices and the importance of regular security assessments to prevent similar vulnerabilities in the future.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-47075 scanner - Information Disclosure vulnerability in Smart Office Web | S4E