« Volver al listado

CVE-2022-41675

Estado: ModificadaAlta (8)—

Un atacante remoto con privilegios de usuario general puede inyectar código malicioso en el contenido del formulario del sitio web de Raiden MAILD Mail Server. Otros usuarios exportan el contenido del formulario como archivo CSV puede desencadenar la ejecución de código arbitrario y permitir que el atacante realice operaciones arbitrarias en el sistema o interrumpa el servicio del lado del usuario.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-41675",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-41675",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-25T14:42:29.307708Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "TEAM JOHNLONG SOFTWARE CO., LTD.",
          "product": "MAILD Mail Server",
          "versions": [
            {
              "status": "affected",
              "version": "4.7"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-11-29T04:15:10.633",
  "references": [
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6738-b78f4-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6738-b78f4-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1236"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1236"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or disrupt service on the user side."
    },
    {
      "lang": "es",
      "value": "Un atacante remoto con privilegios de usuario general puede inyectar código malicioso en el contenido del formulario del sitio web de Raiden MAILD Mail Server. Otros usuarios exportan el contenido del formulario como archivo CSV puede desencadenar la ejecución de código arbitrario y permitir que el atacante realice operaciones arbitrarias en el sistema o interrumpa el servicio del lado del usuario."
    }
  ],
  "lastModified": "2026-06-17T05:03:36.973",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:raidenmaild:raidenmaild:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2FC06351-BF11-4B17-91D3-32D0041D5851",
              "versionEndExcluding": "4.7.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}