7.8
CVE-2022-45338
- EPSS 0.13%
- Veröffentlicht 15.12.2022 23:15:10
- Zuletzt bearbeitet 21.04.2025 15:15:55
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exactsoftware ≫ Exact Synergy Version267 Update- SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp1 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp10 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp11 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp12 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp2 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp3 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp4 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp5 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp6 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp7 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp8 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version267 Updatesp9 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version500 Update- SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version500 Updatesp1 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version500 Updatesp2 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version500 Updatesp3 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version500 Updatesp4 SwEditionenterprise
Exactsoftware ≫ Exact Synergy Version500 Updatesp5 SwEditionenterprise
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.335 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.