PT-2023-17191 · Unknown · Yoga Class Registration System
Carlos Bello
·
Publicado
2023-06-24
·
Atualizado
2023-06-30
·
CVE-2023-1722
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Yoga Class Registration System version 1.0
Description
The issue allows an administrator to execute commands on the server due to incorrect validation of thumbnails of classes uploaded by administrators.
Recommendations
For Yoga Class Registration System version 1.0, consider disabling the thumbnail upload feature for administrators until a proper validation mechanism is implemented to prevent command execution on the server.
Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Yoga Class Registration System