CVE-2022-45889
EUVD-2022-4873625.12.2022, 04:15
Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| planetestream | planet_estream | 𝑥 < 6.72.10.07 |
𝑥
= Vulnerable software versions