7.8

CVE-2022-45338

An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ExactsoftwareExact Synergy Version267 Update- SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp1 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp10 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp11 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp12 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp2 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp3 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp4 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp5 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp6 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp7 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp8 SwEditionenterprise
ExactsoftwareExact Synergy Version267 Updatesp9 SwEditionenterprise
ExactsoftwareExact Synergy Version500 Update- SwEditionenterprise
ExactsoftwareExact Synergy Version500 Updatesp1 SwEditionenterprise
ExactsoftwareExact Synergy Version500 Updatesp2 SwEditionenterprise
ExactsoftwareExact Synergy Version500 Updatesp3 SwEditionenterprise
ExactsoftwareExact Synergy Version500 Updatesp4 SwEditionenterprise
ExactsoftwareExact Synergy Version500 Updatesp5 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.335
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.