PoC Index

CVE-2022-45889

HIGH 7.2EPSS 1.3%

Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.28% chance of exploitation in the next 30 days, 68th percentile
Published
2022-12-25
Updated
2025-04-14

Proof-of-concept exploits (1)

References

Related