First published: Fri May 20 2022(Updated: )
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pharmacy Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30887 is a critical vulnerability in the Pharmacy Management System v1.0 that allows remote code execution (RCE) via a crafted image file.
CVE-2022-30887 affects Pharmacy Management System v1.0 by allowing attackers to execute arbitrary code through the component /php_action/editProductImage.php.
CVE-2022-30887 has a severity rating of critical (9.8).
To fix CVE-2022-30887, it is recommended to update Pharmacy Management System to a patched version or apply the necessary security patches provided by the vendor.
You can find more information about CVE-2022-30887 at the following link: [Pharmacy-Management-System-1.0-Shell-Upload](https://packetstormsecurity.com/files/166786/Pharmacy-Management-System-1.0-Shell-Upload.html).