#rce
CVE-2022-39983: arbitrary file upload in the Instant Developer RD3 frameworkCVE-2022-39983
A library in Instant Developer's RD3 framework allows arbitrary file upload and remote code execution on every web app built with versions prior to 22.5 r23.
CVE-2022-30422: ViewState deserialization in Proietti Planet Time EnterpriseCVE-2022-30422
A default validationKey in Planet Time Enterprise's web.config lets an unauthenticated attacker forge a malicious ViewState and execute commands remotely on the server.