NA

CVE-2022-45892

Published: 25/12/2022 Updated: 04/01/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

In Planet eStream prior to 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

planetestream planet estream

Exploits

Planet eStream versions prior to 6721007 suffer from shell upload, account takeover, broken access control, SQL injection, both persistent and reflective cross site scripting, path traversal, and information disclosure vulnerabilities ...