Proietti Tech srl Planet Time Enterprise code execution | CVE-2022-30422
NAME
Proietti Tech srl Planet Time Enterprise code execution
- Platforms Affected:
Proietti Tech srl Planet Time Enterprise 4.2.0.1
Proietti Tech srl Planet Time Enterprise 4.2.0.0
Proietti Tech srl Planet Time Enterprise 4.1.0.0
Proietti Tech srl Planet Time Enterprise 4.0.0.0
Proietti Tech srl Planet Time Enterprise 3.3.1.0
Proietti Tech srl Planet Time Enterprise 3.3.0.0 - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Gain Access
DESCRIPTION
Proietti Tech srl Planet Time Enterprise could allow a remote attacker to execute arbitrary code on the system. By sending a request with a specially-crafted Viewstate parameter, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Unavailable
MITIGATION
No remedy available as of June 16, 2022.
- Reference Link:
https://www.swascan.com/it/security-advisory-proietti-planet-time-enterprise-cve-2022-30422/ - Reference Link:
https://www.proietti.it/en/index.html
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.