CVE-2022-39179
Last modified
CVE-2022-39179 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file. . EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| College Management System Project | College Management System | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39179?
How severe is CVE-2022-39179?
How do I fix CVE-2022-39179?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-39170libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr …8.8
- CVE-2022-39172A stored XSS in the process overview (bersicht zugewiesener …5.4
- CVE-2022-39173In wolfSSL before 5.5.1, malicious clients can cause a buffe…7.5
- CVE-2022-39176BlueZ before 5.59 allows physically proximate attackers to o…8.8
- CVE-2022-39177BlueZ before 5.59 allows physically proximate attackers to c…8.8
- CVE-2022-39178 Webvendome - webvendome Internal Server IP Disclosure. Send…5.3
- CVE-2022-3918A program using FoundationNetworking in swift-corelibs-found…8.8
- CVE-2022-39180 College Management System v1.0 - SQL Injection (SQLi). By i…9.8
- CVE-2022-39181 GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripti…6.1
- CVE-2022-39182H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Ver…8.8
- CVE-2022-39183Moodle Plugin - SAML Auth may allow Open Redirect through un…6.1
- CVE-2022-39184EXFO - BV-10 Performance Endpoint Unit authentication bypass…9.8
Are you affected by CVE-2022-39179?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
