CVE Published: 23/06/2023 |
CVE Updated: 27/11/2024 |
CVE Year: 2023 Source: Fluid Attacks |
Vendor: Yoga Class Registration System |
Product: Yoga Class Registration System Status : PUBLISHED
CVE-2023-1721 Description
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
Metrics
CVSS Version: 3.1 |
Base Score: 9.1 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H