PT-2022-26317 · Unknown · Wedding Planner

Tr0Ee

·

Published

2022-10-11

·

Updated

2025-05-19

·

CVE-2022-42229

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wedding Planner version 1.0
Description The issue allows for arbitrary code execution via the "package edit.php" endpoint.
Recommendations For version 1.0, update to a version that fixes this issue, if available, or consider disabling access to the "package edit.php" endpoint as a temporary workaround to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-42229

Affected Products

Wedding Planner