CVE-2022-39179
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD
Description
College Management System v1.0 - Authenticated remote code execution.
An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload
.php file that contains malicious code via student.php file.
Affected (1)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
References (2)
Source: cna@cyber.gov.il
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.