cve/2022/CVE-2022-45889.md
2024-06-18 02:51:15 +02:00

812 B

CVE-2022-45889

Description

Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).

POC

Reference

Github