Vulnerability Description
In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wedding Management System Project | Wedding Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/k0xx11/bug_report/blob/main/vendors/codeastro.com/wedding-manExploitThird Party Advisory
- https://github.com/k0xx11/bug_report/blob/main/vendors/codeastro.com/wedding-manExploitThird Party Advisory
FAQ
What is CVE-2022-30820?
CVE-2022-30820 is a vulnerability with a CVSS score of 8.8 (HIGH). In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.
How severe is CVE-2022-30820?
CVE-2022-30820 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30820?
Check the references section above for vendor advisories and patch information. Affected products include: Wedding Management System Project Wedding Management System.