CVE-2022-32430 is an access control vulnerability in Lin CMS Spring Boot v0.2.1 that allows unauthenticated attackers to access backend information and functions. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with no user interaction, leading to high confidentiality impact. While not currently in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 99/100 indicate a significant likelihood of exploitation. Although there is no public exploit code on Metasploit or ExploitDB, Nuclei templates exist for detecting a default JWT token, and the lack of community discussion or media coverage is typical for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.1CPE matchmatch criteria | cpe:2.3:a:talelin:lin-cms-spring-boot:0.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.