PT-2022-24793 · Unknown · College Management System
Liav Gutman
·
Published
2022-11-17
·
Updated
2025-04-28
·
CVE-2022-39179
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
College Management System version 1.0
Description
The issue allows an admin user to upload a .php file containing malicious code via the student.php file, potentially leading to remote code execution. The authentication required for this action can be bypassed using SQL Injection, as mentioned in another report.
Recommendations
For College Management System version 1.0, consider disabling the upload functionality in the student.php file until a patch is available to prevent the upload of malicious .php files. Restrict access to the student.php file to minimize the risk of exploitation. Avoid using the student.php file for uploading any files until the issue is resolved.
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
College Management System