7.8

CVE-2022-45338

An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exactsoftware ≫ Exact Synergy Version 267 Update - SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp1 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp10 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp11 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp12 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp2 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp3 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp4 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp5 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp6 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp7 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp8 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp9 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update - SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp1 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp2 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp3 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp4 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp5 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.126
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADP 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://gist.github.com/MaxRozendaal/633b34a4675b60caed736e5ffe28f272
Third Party Advisory