CVE Published: 17/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: INCD |
Vendor: College Management |
Product: College Management System v1.0 Status : PUBLISHED
CVE-2022-39179 Description
College Management System v1.0 - Authenticated remote code execution.
An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload
.php file that contains malicious code via student.php file.
Metrics
CVSS Version: 3.1 |
Base Score: 7.2 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H