First published: Fri Aug 12 2022(Updated: )
A vulnerability was found in SourceCodester Zoo Management System. It has been classified as critical. Affected is an unknown function of the file /pages/apply_vacancy.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-206250 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zoo Management System Project Zoo Management System | ||
PHPGURUKUL Zoo Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-2804 is critical with a CVSS score of 9.8.
The affected software of CVE-2022-2804 is Zoo Management System Project Zoo Management System.
CVE-2022-2804 allows for unrestricted file upload and can be exploited remotely. This can lead to unauthorized access to the system.
The CWE ID for CVE-2022-2804 is CWE-434.
To fix CVE-2022-2804, it is recommended to apply the latest patch or update provided by the vendor.