CVE-2022-3458: SourceCodester Human Resource Management System Image File employeeview.php unrestricted upload
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /employeeview.php of the component Image File Handler. The manipulation leads to unrestricted upload. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-210559.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3458?
CVE-2022-3458 is classified as a critical vulnerability.
How does CVE-2022-3458 affect the Human Resource Management System?
CVE-2022-3458 affects the file /employeeview.php in the Image File Handler component, allowing unrestricted file uploads.
What versions of the Human Resource Management System are affected by CVE-2022-3458?
CVE-2022-3458 affects version 1.0 of the SourceCodester Human Resource Management System.
How do I fix CVE-2022-3458?
To fix CVE-2022-3458, ensure proper file upload constraints are implemented and validate file types.
Is there a patch available for CVE-2022-3458?
As of now, check with the vendor for any available patches to address CVE-2022-3458.