Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-25T00:00:00

Updated: 2022-12-25T00:00:00

Reserved: 2022-11-25T00:00:00


Link: CVE-2022-45889

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-12-25T04:15:07.660

Modified: 2023-01-04T16:44:52.373


Link: CVE-2022-45889

JSON object: View

cve-icon Redhat Information

No data.

CWE