PT-2022-20337 · Unknown · Wedding Management System

Published

2022-05-31

·

Updated

2022-06-10

·

CVE-2022-30822

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wedding Management System version 1.0
Description The issue concerns an arbitrary file upload vulnerability located in the picture upload point of the "users profile.php" file.
Recommendations For Wedding Management System version 1.0, consider restricting access to the "users profile.php" file to prevent exploitation of the arbitrary file upload vulnerability until a patch is available.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30822

Affected Products

Wedding Management System