7.2
CVSSv3

CVE-2022-45889

Published: 25/12/2022 Updated: 04/01/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

Planet eStream prior to 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

planetestream planet estream

Exploits

Planet eStream versions prior to 6721007 suffer from shell upload, account takeover, broken access control, SQL injection, both persistent and reflective cross site scripting, path traversal, and information disclosure vulnerabilities ...