CVE-2022-2744: SourceCodester Gym Management System Background Management add_exercises.php unrestricted upload
Published Aug 11, 2022
·Updated
A vulnerability, which was classified as critical, has been found in SourceCodester Gym Management System. Affected by this issue is some unknown functionality of the file /admin/addexercises.php of the component Background Management. The manipulation of the argument exerimg leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-206012.
Affected Software
1 affected component
Gym Management System Project Gym Management System
Event History
Aug 11, 2022
CVE Published
via MITRE·04:55 AM
Data Sourced
via MITRE·04:55 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-2744.
2
What is the severity of CVE-2022-2744?
The severity of CVE-2022-2744 is critical (9.8).
3
Which component of SourceCodester Gym Management System is affected by CVE-2022-2744?
The component affected by CVE-2022-2744 is Background Management.
4
What is the risk of CVE-2022-2744?
CVE-2022-2744 poses a high risk as it allows for unrestricted manipulation of the exer_img parameter.
5
Is there a fix for CVE-2022-2744?
There is no information available about a fix for CVE-2022-2744 at this time.