CVE-2022-43436 describes a critical file upload vulnerability in the EasyTest application, specifically within its easy_test_project component. An authenticated general user can exploit insufficient filtering of special characters and file types to upload and execute arbitrary files. This allows for high impact on confidentiality, integrity, and availability, as reflected by its CVSS score of 8.8 (High). While no public exploit code or active exploitation has been observed, and community discussion is minimal, the vulnerability presents a significant risk if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
22h29CPE matchmatch criteria | cpe:2.3:a:easy_test_project:easy_test:22h29:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.