7.8
CVE-2022-45338
- EPSS 0.22%
- Veröffentlicht 15.12.2022 23:15:10
- Zuletzt bearbeitet 21.04.2025 15:15:55
- Erkennungen
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exactsoftware ≫ Exact Synergy Version 267 Update - SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp1 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp10 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp11 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp12 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp2 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp3 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp4 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp5 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp6 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp7 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp8 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 267 Update sp9 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update - SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp1 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp2 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp3 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp4 SwEdition enterprise
Exactsoftware ≫ Exact Synergy Version 500 Update sp5 SwEdition enterprise
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.126 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://gist.github.com/MaxRozendaal/633b34a4675b60caed736e5ffe28f272