CVE-2022-30670

RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploitation of this issue does not require user interaction.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:adobe:robohelp_server:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:11:-:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:11:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:11:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:11:update3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:47

Type Values Removed Values Added
CVSS v2 : 9.0
v3 : 8.8
v2 : 9.0
v3 : unknown

27 Jun 2022, 18:34

Type Values Removed Values Added
References (MISC) https://helpx.adobe.com/security/products/robohelp-server/apsb22-31.html - (MISC) https://helpx.adobe.com/security/products/robohelp-server/apsb22-31.html - Vendor Advisory
First Time Microsoft
Microsoft windows
Adobe
Adobe robohelp Server
CVSS v2 : unknown
v3 : 6.5
v2 : 9.0
v3 : 8.8
CPE cpe:2.3:a:adobe:robohelp_server:11:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:11:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:11:update3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:adobe:robohelp_server:11:-:*:*:*:*:*:*

16 Jun 2022, 17:32

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-16 17:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-30670

Mitre link : CVE-2022-30670

CVE.ORG link : CVE-2022-30670


JSON object : View

Products Affected

microsoft

  • windows

adobe

  • robohelp_server
CWE
CWE-285

Improper Authorization