LiveActive security incident?Get immediate response
CVE Record

CVE-2022-23173: Priority - Priority web Insecure direct object references (IDOR)

this vulnerability affect user that even not allowed to access via the web interface. First of all, the attacker needs to access the "Login menu - demo site" then he can see in this menu all the functionality of the application. If the attacker will try to click on one of the links, he will get an answer that he is not authorized because he needs to log in with credentials. after he performed log in to the system there are some functionalities that the specific user is not allowed to perform because he was configured with low privileges however all the attacker need to do in order to achieve his goals is to change the value of the prog step parameter from 0 to 1 or more and then the attacker could access to some of the functionality the web application that he couldn't perform it before the parameter changed.

MediumCVSS 5.5Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Priority web V22.0 has an authorization weakness where a logged-in low-privilege user may reach application functions they should not be allowed to use. The published impact is moderate, with limited confidentiality, integrity, and availability effects. The supplied sources do not name a patch, workaround, or active exploitation.

Executive priority

Treat this as a moderate business risk if Priority web V22.0 supports sensitive workflows. It is not an unauthenticated internet-takeover issue based on the sources, but it can weaken internal role separation and audit controls.

Technical view

The issue is an IDOR/authorization bypass in Priority web V22.0. A low-privileged authenticated user may alter a workflow or navigation parameter to access role-restricted functions. CVSS 3.1 is 5.5 with low confidentiality, integrity, and availability impacts. No CWE, fixed version, or vendor workaround is provided in the supplied data.

Likely exposure

Organizations running Priority web V22.0 where low-privilege authenticated users can reach the web interface. CVSS lists adjacent attack vector, but the narrative references web interface login; internet exposure is not confirmed by the supplied sources.

Exploitation context

The CVE is not listed as KEV, and the supplied sources do not report active exploitation. Exploitation requires prior low-privilege access and targets missing server-side authorization checks rather than initial compromise.

Researcher notes

Evidence is limited to the CVE description, CVSS vector, affected product, and a government advisory reference. The record does not provide exploit status, patch details, affected configurations beyond V22.0, or CWE mapping. Validate through authorized role-based testing only.

Mitigation direction

  • Identify Priority web V22.0 instances and confirm vendor guidance for fixed builds.
  • Restrict Priority web access to trusted networks and approved users.
  • Review user roles and remove unnecessary low-privilege accounts.
  • Monitor Priority web logs for denied-function access followed by unusual successful access.
  • Ask the vendor whether authorization fixes or configuration mitigations are available.

Validation and detection

  • Inventory Priority web versions and confirm whether V22.0 is deployed.
  • Review application roles against users who can access the web interface.
  • Test authorization boundaries using approved accounts in a controlled environment.
  • Check logs for unexpected access to functions outside assigned roles.
  • Track the gov.il advisory and CVE record for patch or mitigation updates.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-23173 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.5CVSS 3.1MediumCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L2.13.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.5Medium
CVSS 3.1 vector shape for CVE-2022-23173Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
PriorityPriority webV22.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.