← Back to browse · API

CVE-2022-41705

Severity
CRITICAL
CVSS
9.8
EPSS
0.01813
Risk score
39.83
CISA KEV
No
PoC
No
Published
2022-11-25
Modified
2025-04-29
First seen
2026-08-07
Aliases
EUVD-2022-7337, GHSA-G389-RF5P-FG56
Products
Uasoft:Badaso 2.6.3
Sources
euvd EUVD-2022-7337

Description

Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

References