VYPR
Unrated severityNVD Advisory· Published Sep 8, 2022· Updated Aug 3, 2024

CVE-2022-27967

CVE-2022-27967

Description

Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a crafted GET request sent to /WebApp/SettingsExclusion/GetExclusionsProfiles.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cynet 360 Web Portal before v4.5 exposes a list of excluded files and profiles via a crafted GET request to a specific endpoint.

Vulnerability

Cynet 360 Web Portal versions before v4.5 contain an information disclosure vulnerability in the /WebApp/SettingsExclusion/GetExclusionsProfiles endpoint. An attacker can send a crafted GET request to this endpoint to retrieve a list of excluded files and profiles, which are normally intended to be hidden from unauthorized users. [1]

Exploitation

The attacker does not require authentication or special privileges; they only need network access to the Cynet 360 Web Portal. By sending a crafted GET request to /WebApp/SettingsExclusion/GetExclusionsProfiles, the server responds with the list of excluded files and profiles. No user interaction is needed.

Impact

Successful exploitation allows an attacker to obtain a list of excluded files and profiles. This information can reveal which files or paths are excluded from security scanning, potentially enabling the attacker to bypass detection by placing malicious files in those excluded locations. The impact is limited to information disclosure, but it can aid further attacks.

Mitigation

The vulnerability is fixed in Cynet 360 Web Portal version v4.5 and later. Users should upgrade to the latest version. No workarounds are documented in the available references. [1]

References
  1. Platform

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.