CVE-2022-27351: Malicious File Upload
Published Apr 8, 2022
·Updated
Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /publichtml/applyvacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Affected Software
2 affected components
Phpgurukul Zoo Management System=1.0
Zoo Management System Project Zoo Management System=1.0
Event History
Apr 8, 2022
CVE Published
via MITRE·08:23 AM
Data Sourced
via MITRE·08:23 AM
Description
Frequently Asked Questions
1
What is CVE-2022-27351?
CVE-2022-27351 is an arbitrary file upload vulnerability in Zoo Management System v1.0.
2
How does CVE-2022-27351 affect Zoo Management System v1.0?
CVE-2022-27351 allows attackers to execute arbitrary code via a crafted PHP file.
3
What is the severity of CVE-2022-27351?
CVE-2022-27351 has a severity rating of 9.8 (critical).
4
How can an attacker exploit CVE-2022-27351?
An attacker can exploit CVE-2022-27351 by uploading a malicious PHP file through the /public_html/apply_vacancy endpoint.
5
Is there a fix for CVE-2022-27351?
It is recommended to update Zoo Management System v1.0 to a patched version that addresses the arbitrary file upload vulnerability.