High severity7.8NVD Advisory· Published Dec 15, 2022· Updated Jun 17, 2026
CVE-2022-45338
CVE-2022-45338
Description
An arbitrary file upload vulnerability in the profile picture upload function of Exact Synergy Enterprise 267 before 267SP13 and Exact Synergy Enterprise 500 before 500SP6 allows attackers to execute arbitrary code via a crafted SVG file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:exactsoftware:exact_synergy:267:-:*:*:enterprise:*:*:*+ 18 more
- cpe:2.3:a:exactsoftware:exact_synergy:267:-:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp10:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp11:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp12:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp1:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp2:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp3:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp4:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp5:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp6:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp7:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp8:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:267:sp9:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:500:-:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:500:sp1:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:500:sp2:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:500:sp3:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:500:sp4:*:*:enterprise:*:*:*
- cpe:2.3:a:exactsoftware:exact_synergy:500:sp5:*:*:enterprise:*:*:*
- Exact Synergy Enterprise/Exact Synergy Enterprisedescription
- Range: <267SP13, <500SP6
Patches
Vulnerability mechanics
References
1- gist.github.com/MaxRozendaal/633b34a4675b60caed736e5ffe28f272nvdThird Party Advisory
News mentions
0No linked articles in our index yet.