PT-2022-20337 · Unknown · Wedding Management System
Published
2022-05-31
·
Updated
2022-06-10
·
CVE-2022-30822
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wedding Management System version 1.0
Description
The issue concerns an arbitrary file upload vulnerability located in the picture upload point of the "users profile.php" file.
Recommendations
For Wedding Management System version 1.0, consider restricting access to the "users profile.php" file to prevent exploitation of the arbitrary file upload vulnerability until a patch is available.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wedding Management System