← Back to browse · API

CVE-2022-44006

Severity
CRITICAL
CVSS
9.8
EPSS
0.01877
Risk score
39.86
CISA KEV
No
PoC
No
Published
2022-11-16
Modified
2025-04-30
First seen
2026-08-07
Aliases
EUVD-2022-46969, GHSA-V352-9JVG-8C8Q
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-46969

Description

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

References