PT-2022-18825 · Beijing Runnier Network Technology Co. · Open Virtual Simulation Experiment Teaching Management Platform

Published

2022-05-05

·

Updated

2022-05-13

·

CVE-2022-28120

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software version 2.0
Description The issue concerns a file upload vulnerability that can be exploited by an attacker to gain control of the server. This vulnerability allows an attacker to potentially take control of the server, posing a significant security risk.
Recommendations For version 2.0, consider restricting or disabling the file upload feature until a fix is available to prevent potential exploitation. As a temporary workaround, limit access to the file upload functionality to minimize the risk of server compromise.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28120

Affected Products

Open Virtual Simulation Experiment Teaching Management Platform