Vulnerability Description
College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| College Management System Project | College Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://www.gov.il/en/Departments/faq/cve_advisories
- https://www.gov.il/en/Departments/faq/cve_advisories
FAQ
What is CVE-2022-39179?
CVE-2022-39179 is a vulnerability with a CVSS score of 7.2 (HIGH). College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file tha...
How severe is CVE-2022-39179?
CVE-2022-39179 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-39179?
Check the references section above for vendor advisories and patch information. Affected products include: College Management System Project College Management System.