ZeroHour

CVE-2022-45338

CVSS 3.1
7.8 high
EPSS
<1%p13
Published
()
Modified
Description

An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.

Vendors
exactsoftware
Products
exact synergy
Weakness
CWE-434
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.