Back to Database
Status published
High
CVE-2022-24251
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted...
Vulnerability Description
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24251
Credits & Attribution
No credits recorded in the NVD database.
More from extensis
View All →CVE-2022-24255
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which...
High
8.8
CVE-2022-24254
An unrestricted file upload vulnerability in the Backup/Restore Archive component...
High
8.8
CVE-2022-24253
Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted...
High
8.8
CVE-2022-24252
An unrestricted file upload vulnerability in the FileTransferServlet component of...
High
8.8
CVE-2017-18006
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind...
Medium
6.1
Affected Vendor
extensis
View all reports →Affected Software
portfolio
Vulnerable Versions:
4.0
Timeline
Official Publish:
March 1st, 2022
Last Modified:
July 9th, 2026
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.