Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Li4U

#15329of 53,624
17.6Total CVSS
Vulnerabilities · 2
High
2
PT-2022-25924
8.8
2022-10-14
Unknown · Wedding Planner · CVE-2022-41538
**Name of the Vulnerable Software and Affected Versions** Wedding Planner version 1.0 **Description** The issue is related to an arbitrary file upload vulnerability in the /Wedding-Management-PHP/admin/photos add.php component. This allows attackers to execute arbitrary code via a crafted PHP file. **Recommendations** For Wedding Planner version 1.0, consider restricting access to the /Wedding-Management-PHP/admin/photos add.php component to prevent arbitrary file uploads until a fix is available. As a temporary workaround, disabling the file upload functionality in this component can help minimize the risk of exploitation.
PT-2022-25925
8.8
2022-10-14
Unknown · Wedding Planner · CVE-2022-41539
**Name of the Vulnerable Software and Affected Versions** Wedding Planner version 1.0 **Description** The issue is related to an arbitrary file upload vulnerability in the /admin/users add.php component. This allows attackers to execute arbitrary code via a crafted PHP file. **Recommendations** For Wedding Planner version 1.0, consider disabling the file upload functionality in the /admin/users add.php component until a patch is available. Restrict access to this component to minimize the risk of exploitation.