CVE-2022-22111
Estado: ModificadaAlta (8.8)—
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.00%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
- CWE-862
Referencias
- https://github.com/Bottelet/DaybydayCRM/commit/fe842ea5ede237443f1f45a99aeb839133115d8b
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22111
- https://github.com/Bottelet/DaybydayCRM/commit/fe842ea5ede237443f1f45a99aeb839133115d8b
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22111
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-22111",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vulnerabilitylab@mend.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "vulnerabilitylab@mend.io",
"affectedData": [
{
"vendor": "Bottelet",
"product": "DaybydayCRM",
"versions": [
{
"status": "affected",
"version": "2.2.0"
}
]
},
{
"vendor": "Bottelet",
"product": "flarepoint",
"versions": [
{
"status": "affected",
"version": "2.2.0"
}
]
}
]
}
],
"published": "2022-01-05T15:15:07.990",
"references": [
{
"url": "https://github.com/Bottelet/DaybydayCRM/commit/fe842ea5ede237443f1f45a99aeb839133115d8b",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22111",
"tags": [
"Third Party Advisory"
],
"source": "vulnerabilitylab@mend.io"
},
{
"url": "https://github.com/Bottelet/DaybydayCRM/commit/fe842ea5ede237443f1f45a99aeb839133115d8b",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-22111",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnerabilitylab@mend.io",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application."
},
{
"lang": "es",
"value": "En DayByDay CRM, versión 2.2.0, es vulnerable a una falta de autorización. Cualquier usuario de la aplicación que tenga habilitado el permiso de actualización de usuarios es capaz de cambiar la contraseña de otros usuarios, incluida la del administrador. Esto permite al atacante conseguir acceso al usuario con más privilegios de la aplicación."
}
],
"lastModified": "2026-06-17T04:27:47.230",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:daybydaycrm:daybyday_crm:2.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1A83CDA-4210-4151-BAAC-F16FA2DAAB4C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vulnerabilitylab@mend.io"
}