CVE-2022-31259
ADVISORY - githubSummary
The route lookup process in beego prior to 1.12.9 and 2.x prior to 2.0.3 allows attackers to bypass access control. When a /p1
/p2
/:name
route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).
EPSS Score: 0.00201 (0.585)
Common Weakness Enumeration (CWE)
ADVISORY - nist
ADVISORY - github
Improper Access Control
NIST
CREATED
UPDATED
ADVISORY IDCVE-2022-31259
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)
GitHub
CREATED
UPDATED
ADVISORY IDGHSA-qx32-f6g6-fcfr
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
GoLang
CREATED
UPDATED
ADVISORY IDGO-2022-0463
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
intheWild
CREATED
UPDATED
ADVISORY IDCVE-2022-31259
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-