PT-2022-26745 · Unknown · Vehicle Booking System

Tr0E

·

Published

2022-11-01

·

Updated

2022-11-02

·

CVE-2022-43083

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vehicle Booking System version 1.0
Description The issue allows attackers to execute arbitrary code via a crafted PHP file due to an arbitrary file upload vulnerability in the admin-add-vehicle.php file.
Recommendations For Vehicle Booking System version 1.0, consider removing or restricting access to the admin-add-vehicle.php file until a patch is available. As a temporary workaround, restrict the types of files that can be uploaded through this interface to prevent the execution of malicious code.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-43083

Affected Products

Vehicle Booking System