NA

CVE-2022-44006

Published: 16/11/2022 Updated: 20/11/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

backclick backclick 5.9.63