Unrestricted File Upload Vulnerability in SolarView Compact Products
CVE-2022-44354

9.8CRITICAL

Key Information:

Vendor

Contec

Vendor
CVE Published:
29 November 2022

What is CVE-2022-44354?

The SolarView Compact 4.0 and 5.0 products present a security vulnerability that allows attackers to perform an unrestricted file upload through a crafted PHP file, potentially leading to unauthorized access and execution of malicious code on the server. This issue can compromise the integrity and availability of the application, emphasizing the need for proper file validation mechanisms.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.