PT-2023-14690 · Unknown · Future-Depth Institutional Management Website

Hucliluo

·

Published

2023-02-08

·

Updated

2025-03-25

·

CVE-2022-45527

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Future-Depth Institutional Management Website (IMS) version 1.0
Description The issue allows unauthorized attackers to directly upload malicious files to the courseimg directory. This is a result of a file upload vulnerability in the software.
Recommendations For Future-Depth Institutional Management Website (IMS) version 1.0, consider restricting access to the courseimg directory to prevent unauthorized file uploads until a patch is available. As a temporary workaround, disabling the file upload feature can help minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45527

Affected Products

Future-Depth Institutional Management Website