Security Advisory

CVE-2022-23771

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-10-17 00:00:00
Last updated 2025-05-09 14:49:10
Assigner krcert
State PUBLISHED

Description

This vulnerability occurs in user accounts creation and deleteion related pages of IPTIME NAS products. The vulnerability could be exploited by a lack of validation when a POST request is made to this page. An attacker can use this vulnerability to or delete user accounts, or to escalate arbitrary user privileges.