CVE-2022-44000

CRITICAL

BACKCLICK Professional <5.9.63 - RCE

Title source: llm
STIX 2.1

Description

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

Scores

CVSS v3 9.8
EPSS 0.0036
EPSS Percentile 58.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306 CWE-913
Status published
Products (1)
backclick/backclick 5.9.63
Published Nov 16, 2022
Tracked Since Feb 18, 2026