PT-2022-25846 · Unknown · Church Management System

Cokutau-Ch

·

Published

2022-10-11

·

Updated

2022-10-13

·

CVE-2022-41406

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Church Management System version 1.0
Description The issue concerns an arbitrary file upload vulnerability in the /admin/admin pic.php component. This allows attackers to execute arbitrary code via a crafted PHP file. The "arbitrary file upload" term refers to the ability of an attacker to upload files of any type, potentially leading to the execution of malicious code.
Recommendations For Church Management System version 1.0, consider disabling the /admin/admin pic.php component until a patch is available to prevent arbitrary file uploads. Restrict access to this component to minimize the risk of exploitation. Avoid using this component for file uploads until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-41406

Affected Products

Church Management System