CVE-2023-22275
Adobe RoboHelp Server vulnerability analysis and mitigation

Overview

Adobe RoboHelp Server versions 11.4 and earlier are affected by an SQL Injection vulnerability (CVE-2023-22275) that was discovered and disclosed in November 2023. The vulnerability specifically exists within the GetNewUserId method and could lead to information disclosure when exploited by an unauthenticated attacker. This security flaw does not require any user interaction for exploitation (NVD, ZDI).

Technical details

The vulnerability is classified as an Improper Neutralization of Special Elements used in an SQL Command (CWE-89). It has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The specific flaw exists within the GetNewUserId method, where there is inadequate validation of user-supplied strings before they are used in SQL query construction (ZDI).

Impact

When successfully exploited, this vulnerability allows attackers to disclose sensitive information in the context of the application database. The high CVSS score reflects the significant potential for information disclosure, though the vulnerability does not affect system integrity or availability (ZDI).

Mitigation and workarounds

Adobe has released a security update to address this vulnerability. Users are advised to update their RoboHelp Server installations to the latest version that includes the security fix (ZDI).

Additional resources


SourceThis report was generated using AI

Related Adobe RoboHelp Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-22275HIGH7.5
  • Adobe RoboHelp ServerAdobe RoboHelp Server
  • cpe:2.3:a:adobe:robohelp_server
NoNoNov 17, 2023
CVE-2023-22274HIGH7.5
  • Adobe RoboHelp ServerAdobe RoboHelp Server
  • cpe:2.3:a:adobe:robohelp_server
NoNoNov 17, 2023
CVE-2023-22272HIGH7.5
  • Adobe RoboHelp ServerAdobe RoboHelp Server
  • cpe:2.3:a:adobe:robohelp_server
NoNoNov 17, 2023
CVE-2023-22273HIGH7.2
  • Adobe RoboHelp ServerAdobe RoboHelp Server
  • cpe:2.3:a:adobe:robohelp_server
NoNoNov 17, 2023
CVE-2023-22268MEDIUM6.5
  • Adobe RoboHelp ServerAdobe RoboHelp Server
  • cpe:2.3:a:adobe:robohelp_server
NoNoNov 17, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management