PT-2022-25193 · Unknown · Simple College Website

Published

2022-09-22

·

Updated

2025-05-27

·

CVE-2022-40087

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple College Website version 1.0
Description The issue allows attackers to execute arbitrary code via a crafted PHP file, leveraging an arbitrary file write vulnerability. This is achieved through the file put contents() function.
Recommendations For Simple College Website version 1.0, as a temporary workaround, consider disabling the file put contents() function until a patch is available. Restrict access to sensitive areas of the website to minimize the risk of exploitation. Avoid using the file put contents() function in critical parts of the application until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-40087

Affected Products

Simple College Website