Aller au contenu

Fiche vulnérabilité

CVE-2022-45889 : faille élevée planetestream planet estream (CVSS 7.2)

Description

Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
25 déc. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • planetestream planet estream

Références

Rechercher une autre vulnérabilité dans la base CVE