PT-2022-22435 · Sourcecodester · Sourcecodester Human Resource Management System

Draco

·

Published

2022-10-13

·

Updated

2024-01-25

·

CVE-2022-3492

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Human Resource Management System version 1.0
Description A critical issue was found in the Profile Photo Handler component, where manipulation of the argument parameter leads to os command injection. This issue can be initiated remotely.
Recommendations For version 1.0, consider restricting access to the Profile Photo Handler component to minimize the risk of exploitation. As a temporary workaround, avoid using the argument parameter in the affected component until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Improper Neutralization

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-3492

Affected Products

Sourcecodester Human Resource Management System