PT-2022-22144 · Sourcecodester · Sourcecodester Web-Based Student Clearance System
Akash Pandey
+1
·
Published
2022-10-09
·
Updated
2023-11-30
·
CVE-2022-3436
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Web-Based Student Clearance System version 1.0
Description
A critical issue was found in the Photo Handler component, specifically in the file edit-photo.php, allowing for unrestricted upload. This can be exploited remotely.
Recommendations
For version 1.0, consider disabling the edit-photo.php file or restricting access to it until a fix is available. As a temporary workaround, restrict the upload functionality in the Photo Handler component to minimize the risk of exploitation.
Fix
Incorrect Privilege Assignment
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Web-Based Student Clearance System