PoC Index

CVE-2022-47878

CRITICAL 9.1EPSS 35.7%

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS
35.72% chance of exploitation in the next 30 days, 98th percentile
Published
2023-05-02
Updated
2025-11-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related