Unknown · Roncoo Education · CVE-2022-29632
**Name of the Vulnerable Software and Affected Versions**
Roncoo Education version 9.0.0
**Description**
The issue is related to an arbitrary file upload vulnerability in the `/course/api/upload/pic` component, allowing attackers to execute arbitrary code via a crafted file.
**Recommendations**
For Roncoo Education version 9.0.0, consider disabling the `/course/api/upload/pic` component until a patch is available to prevent arbitrary file uploads and subsequent code execution. Restrict access to this component to minimize the risk of exploitation. Avoid using this component for file uploads until the issue is resolved.