Vulnerability Details CVE-2022-43340
A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and grant Administrator rights to regular users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 27.6%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-43340
-
cpe:2.3:a:dzzoffice:dzzoffice:2.02.1