High severity8.8NVD Advisory· Published Aug 21, 2022· Updated Jun 17, 2026
CVE-2022-2921
CVE-2022-2921
Description
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
notrinos/notrinos-erpPackagist | < 0.7 | 0.7 |
Affected products
2- Range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/notrinos/notrinoserp/commit/1b9903f4deea3289872793e60d730c63ecbf7b45nvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/51b32a1c-946b-4390-a212-b6c4b6e4115cnvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-44w5-q257-8428ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-2921ghsaADVISORY
News mentions
0No linked articles in our index yet.