CVE-2022-2804: SourceCodester Zoo Management System apply_vacancy.php unrestricted upload
A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/applyvacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2804?
The severity of CVE-2022-2804 is critical with a CVSS score of 9.8.
What is the affected software of CVE-2022-2804?
The affected software of CVE-2022-2804 is Zoo Management System Project Zoo Management System.
How does CVE-2022-2804 impact the application?
CVE-2022-2804 allows for unrestricted file upload and can be exploited remotely. This can lead to unauthorized access to the system.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-2804?
The CWE ID for CVE-2022-2804 is CWE-434.
How can I fix CVE-2022-2804?
To fix CVE-2022-2804, it is recommended to apply the latest patch or update provided by the vendor.