# CVE-2022-2921

## Summary

- **CVE ID:** CVE-2022-2921
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-359
- **Published:** Aug 21, 2022
- **Last Modified:** Mar 13, 2026

## Description

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions.

## Affected Products

- notrinos — notrinos/notrinoserp (unspecified)

## References

- [CNA](https://huntr.dev/bounties/51b32a1c-946b-4390-a212-b6c4b6e4115c)
- [CNA](https://github.com/notrinos/notrinoserp/commit/1b9903f4deea3289872793e60d730c63ecbf7b45)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.33%
- **EPSS Percentile:** 69.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._