CVE-2022-47076 is a high-severity information disclosure vulnerability affecting Smart Office Web versions 20.28 and earlier. An unauthenticated attacker can view sensitive information by accessing the DisplayParallelLogData.aspx page. This vulnerability has a CVSS score of 7.5, indicating a high impact on confidentiality with no user interaction required. While not actively exploited in the wild or on the CISA KEV catalog, a public exploit (EDB-51539) exists, and its EPSS score suggests a higher-than-average likelihood of exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.28CPE matchmatch criteria | cpe:2.3:a:smartofficepayroll:smartoffice:*:*:*:*:web:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.