CVE-2022-26645: Malicious File Upload
Published Mar 30, 2022
·Updated
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
Affected Software
2 affected components
Banking System Project Banking System=1.0
oretnom23 Banking System=1.0
Event History
Mar 30, 2022
CVE Published
via MITRE·10:23 PM
Data Sourced
via MITRE·10:23 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-26645?
CVE-2022-26645 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2022-26645?
To fix CVE-2022-26645, ensure that you upgrade to a patched version of the Online Banking System that addresses this vulnerability.
3
What systems are impacted by CVE-2022-26645?
CVE-2022-26645 affects Online Banking System Protect version 1.0.
4
What type of vulnerability is CVE-2022-26645?
CVE-2022-26645 is classified as a remote code execution (RCE) vulnerability.
5
How does CVE-2022-26645 exploit the system?
CVE-2022-26645 allows attackers to exploit the Upload Image function to execute arbitrary code via a crafted PHP file.