Vulnerability Description
Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Garage Management System Project | Garage Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/REAExploitThird Party Advisory
- https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysqlProduct
- https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/REAExploitThird Party Advisory
- https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysqlProduct
FAQ
What is CVE-2022-36667?
CVE-2022-36667 is a vulnerability with a CVSS score of 8.8 (HIGH). Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the uploa...
How severe is CVE-2022-36667?
CVE-2022-36667 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36667?
Check the references section above for vendor advisories and patch information. Affected products include: Garage Management System Project Garage Management System.