CVE-2022-39179
Last modified
CVE-2022-39179 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file. . EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| College Management System Project | College Management System | 1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-39179?
How severe is CVE-2022-39179?
How do I fix CVE-2022-39179?
Are you affected by CVE-2022-39179?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
