CVE-2022-39179

College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:college_management_system_project:college_management_system:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:17

Type Values Removed Values Added
References () https://www.gov.il/en/Departments/faq/cve_advisories - () https://www.gov.il/en/Departments/faq/cve_advisories -

25 Oct 2023, 18:17

Type Values Removed Values Added
References
  • {'url': 'https://www.gov.il/en/departments/faq/cve_advisories', 'name': 'https://www.gov.il/en/departments/faq/cve_advisories', 'tags': ['Third Party Advisory'], 'refsource': 'MISC'}
  • (MISC) https://www.gov.il/en/Departments/faq/cve_advisories -
Summary College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file. College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

Information

Published : 2022-11-17 23:15

Updated : 2024-11-21 07:17


NVD link : CVE-2022-39179

Mitre link : CVE-2022-39179

CVE.ORG link : CVE-2022-39179


JSON object : View

Products Affected

college_management_system_project

  • college_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')