PT-2022-25195 · Unknown · Simple College Website

Published

2022-09-22

·

Updated

2022-09-26

·

CVE-2022-40089

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple College Website version 1.0
Description A remote file inclusion issue allows attackers to execute arbitrary code via a crafted PHP file. This issue is exploitable when the allow url include directive is set to On.
Recommendations For Simple College Website version 1.0, consider setting the allow url include directive to Off to prevent exploitation. As a temporary workaround, restrict the execution of arbitrary PHP files until a patch is available.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-40089

Affected Products

Simple College Website