PT-2022-4827 · Syncovery · Syncovery

Jan Rude

·

Published

2022-09-15

·

Updated

2023-08-08

·

CVE-2022-36534

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Syncovery versions 9.47x and below
Description The issue is related to remote code execution via the Job ExecuteBefore and Job ExecuteAfter parameters at the "post profilesettings.php" endpoint. It is associated with a lack of data sanitization at the management level. Exploitation of this issue may allow a remote attacker to elevate their privileges.
Recommendations For Syncovery versions 9.47x and below, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-05853
CVE-2022-36534

Affected Products

Syncovery