PT-2022-27068 · Unknown · Backclick Professional

Published

2022-11-16

·

Updated

2022-11-20

·

CVE-2022-44006

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BACKCLICK Professional version 5.9.63
Description An issue was discovered due to improper validation or sanitization of upload filenames, allowing an externally reachable, unauthenticated update function to write files outside the intended target location. This can lead to remote code execution, for example, by uploading an executable file.
Recommendations For BACKCLICK Professional version 5.9.63, consider disabling the unauthenticated update function until a patch is available to prevent writing files outside the intended target location and minimize the risk of remote code execution. Restrict access to the update function to minimize the risk of exploitation. Avoid using the update function with unvalidated or unsanitized filenames until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-44006

Affected Products

Backclick Professional