9.8
CVSSv3

CVE-2022-45896

Published: 25/12/2022 Updated: 04/01/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Planet eStream prior to 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

planetestream planet estream

Exploits

Planet eStream versions prior to 6721007 suffer from shell upload, account takeover, broken access control, SQL injection, both persistent and reflective cross site scripting, path traversal, and information disclosure vulnerabilities ...