PT-2022-26211 · Unknown · Wedding Planner

李趴菜

·

Published

2022-10-11

·

Updated

2022-10-11

·

CVE-2022-42034

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wedding Planner version 1.0
Description The issue allows for arbitrary code execution via the users profile.php file.
Recommendations For Wedding Planner version 1.0, consider restricting access to the users profile.php file until a patch is available.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-42034

Affected Products

Wedding Planner