PT-2023-17191 · Unknown · Yoga Class Registration System
Carlos Bello
·
Published
2023-06-24
·
Updated
2023-06-30
·
CVE-2023-1722
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Yoga Class Registration System version 1.0
Description
The issue allows an administrator to execute commands on the server due to incorrect validation of thumbnails of classes uploaded by administrators.
Recommendations
For Yoga Class Registration System version 1.0, consider disabling the thumbnail upload feature for administrators until a proper validation mechanism is implemented to prevent command execution on the server.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yoga Class Registration System