PT-2022-25830 · Unknown · Online Leave Management System

Hegeoo

·

Published

2022-10-07

·

Updated

2022-10-11

·

CVE-2022-41379

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Leave Management System version 1.0
Description The issue concerns an arbitrary file upload vulnerability in the component /leave system/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Recommendations For Online Leave Management System version 1.0, consider disabling the file upload functionality in the /leave system/classes/Users.php?f=save component until a patch is available. Restrict access to this component to minimize the risk of exploitation. Avoid using this component for file uploads until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-41379

Affected Products

Online Leave Management System