Vulnerability Description
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yoga Class Registration System Project | Yoga Class Registration System | 1.0 |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/wyckoff/ExploitThird Party Advisory
- https://www.sourcecodester.com/php/16097/yoga-class-registration-system-php-and-Product
- https://fluidattacks.com/advisories/wyckoff/ExploitThird Party Advisory
- https://www.sourcecodester.com/php/16097/yoga-class-registration-system-php-and-Product
FAQ
What is CVE-2023-1722?
CVE-2023-1722 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes...
How severe is CVE-2023-1722?
CVE-2023-1722 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-1722?
Check the references section above for vendor advisories and patch information. Affected products include: Yoga Class Registration System Project Yoga Class Registration System.