PT-2022-18788 · Unknown · Car Rental System
Published
2022-04-04
·
Updated
2022-06-05
·
CVE-2022-28062
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Car Rental System version 1.0
Description
The issue concerns an arbitrary file upload vulnerability via the Add Car component, allowing attackers to upload a webshell and execute arbitrary code.
Recommendations
For Car Rental System version 1.0, consider disabling the file upload functionality in the Add Car component until a patch is available to prevent exploitation. Restrict access to the Add Car component to minimize the risk of arbitrary code execution.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Car Rental System