Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-44006

Опубликовано: 16 нояб. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:backclick:backclick:5.9.63:*:*:*:professional:*:*:*

EPSS

Процентиль: 90%
0.05706
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 9.8
github
около 3 лет назад

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

EPSS

Процентиль: 90%
0.05706
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-22