A vulnerability was found in SourceCodester Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the component /card/index.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/CyberThoth/CVE/blob/main/CVE/Library%20Management%20System%20with%20QR%20code%20Attendance/File_Upload/POC.md | Exploit Third Party Advisory |
https://vuldb.com/?id.202758 | Third Party Advisory VDB Entry |
https://github.com/CyberThoth/CVE/blob/main/CVE/Library%20Management%20System%20with%20QR%20code%20Attendance/File_Upload/POC.md | Exploit Third Party Advisory |
https://vuldb.com/?id.202758 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:00
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 6.3 |
References | () https://github.com/CyberThoth/CVE/blob/main/CVE/Library%20Management%20System%20with%20QR%20code%20Attendance/File_Upload/POC.md - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?id.202758 - Third Party Advisory, VDB Entry |
Information
Published : 2022-06-27 07:15
Updated : 2024-11-21 07:00
NVD link : CVE-2022-2212
Mitre link : CVE-2022-2212
CVE.ORG link : CVE-2022-2212
JSON object : View
Products Affected
library_management_system_project
- library_management_system
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type