← Vulnerability feed

Vulnerability record · CVE-2023-22272 · published 17 November 2023

CVE-2023-22272: Adobe robohelp server improper input validation vulnerability

Adobe · Robohelp Server

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

7.5 CVSS 3.1 High EPSS 1.4% · top 28.7% CWE-20 · Improper input validation
7.5CVSS 3.1 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Input Validation vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22272 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-3068Adobe RoboHelp Server unrestricted file upload enables code executionAdobe RoboHelp Server 8 fails to restrict file uploads through the RoboHelpServer Servlet (robohelp/server). An attacker can upload a Java Archive fi…EPSS 78%analysed8.8CVE-2022-30670Adobe robohelp server improper authorization vulnerabilityRoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalatio…EPSS 1.5%8.8CVE-2021-28588Adobe robohelp server path traversal vulnerabilityAdobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authe…EPSS 6.2%7.8CVE-2021-42727Adobe robohelp server out-of-bounds write vulnerabilityAdobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in …EPSS 39%7.5CVE-2023-22274Adobe robohelp server xml external entity (xxe) vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…EPSS 1.5%7.5CVE-2023-22275Adobe robohelp server sql injection vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection…EPSS 1.3%7.2CVE-2023-22273Adobe robohelp server path traversal vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…EPSS 1.9%6.5CVE-2023-22268Adobe robohelp server sql injection vulnerabilityAdobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-22272), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.