CVE-2022-27967
Description
Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a crafted GET request sent to /WebApp/SettingsExclusion/GetExclusionsProfiles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cynet 360 Web Portal before v4.5 exposes a list of excluded files and profiles via a crafted GET request to a specific endpoint.
Vulnerability
Cynet 360 Web Portal versions before v4.5 contain an information disclosure vulnerability in the /WebApp/SettingsExclusion/GetExclusionsProfiles endpoint. An attacker can send a crafted GET request to this endpoint to retrieve a list of excluded files and profiles, which are normally intended to be hidden from unauthorized users. [1]
Exploitation
The attacker does not require authentication or special privileges; they only need network access to the Cynet 360 Web Portal. By sending a crafted GET request to /WebApp/SettingsExclusion/GetExclusionsProfiles, the server responds with the list of excluded files and profiles. No user interaction is needed.
Impact
Successful exploitation allows an attacker to obtain a list of excluded files and profiles. This information can reveal which files or paths are excluded from security scanning, potentially enabling the attacker to bypass detection by placing malicious files in those excluded locations. The impact is limited to information disclosure, but it can aid further attacks.
Mitigation
The vulnerability is fixed in Cynet 360 Web Portal version v4.5 and later. Users should upgrade to the latest version. No workarounds are documented in the available references. [1]
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Cynet/360 Web Portaldescription
- Range: <=4.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.cynet.com/platform/mitrex_refsource_MISC
- www.srlabs.de/bites/edr-securitymitrex_refsource_MISC
News mentions
0No linked articles in our index yet.