CVE-2022-2749: SourceCodester Gym Management System unrestricted upload
A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/index.php?viewexercises. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-206017 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2749?
CVE-2022-2749 has been classified as a critical vulnerability.
How do I fix CVE-2022-2749?
To fix CVE-2022-2749, implement strict file upload validation and restrict the file types that can be uploaded.
What does CVE-2022-2749 affect?
CVE-2022-2749 affects the Gym Management System through an unrestricted file upload vulnerability.
How can CVE-2022-2749 be exploited?
CVE-2022-2749 can be exploited by manipulating the file /mygym/admin/index.php?view_exercises to upload unauthorized files.
Who is affected by CVE-2022-2749?
Users of the Gym Management System Project are affected by CVE-2022-2749.