High severity7.5NVD Advisory· Published Jun 2, 2022· Updated Jul 9, 2026
CVE-2022-24581
CVE-2022-24581
Description
ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- ACEweb/ACEweb Online Portaldescription
- Range: = 3.5.065
Patches
Vulnerability mechanics
References
1- www.aceware.com/forum/viewtopic.phpnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.