6.1
CVSSv3

CVE-2022-45890

Published: 25/12/2022 Updated: 04/01/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

In Planet eStream prior to 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

planetestream planet estream

Exploits

Planet eStream versions prior to 6721007 suffer from shell upload, account takeover, broken access control, SQL injection, both persistent and reflective cross site scripting, path traversal, and information disclosure vulnerabilities ...