← Retour aux CVEs
CVE-2022-36667
HIGH8.8
Description
Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.
Details CVE
Score CVSS v3.18.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie9/14/2022
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
garage_management_system_project:garage_management_system
Faiblesses (CWE)
CWE-434
References
https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.md(cve@mitre.org)
https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.html(cve@mitre.org)
https://github.com/saitamang/POC-DUMP/blob/main/Garage%20Management%20System/README.md(af854a3a-2127-422b-91ae-364da2661108)
https://www.sourcecodester.com/php/15485/garage-management-system-using-phpmysql-source-code.html(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.