PT-2022-27667 · Unknown · Planet Estream

Hrvoje Filakovic

+2

·

Published

2022-12-25

·

Updated

2023-01-04

·

CVE-2022-45889

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Planet eStream versions prior to 6.72.10.07
Description The issue allows a remote attacker, who is a publisher or admin, to obtain access to all records stored in the database and execute arbitrary SQL commands via Search, specifically through the flt parameter in the "StatisticsResults.aspx" page.
Recommendations For versions prior to 6.72.10.07, update to version 6.72.10.07 or later to resolve the issue. As a temporary workaround, consider restricting access to the StatisticsResults.aspx page or disabling the flt parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-45889

Affected Products

Planet Estream