First published: Mon Oct 17 2022(Updated: )
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-211049 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Cold Storage Management System Project Simple Cold Storage Management System | =1.0 | |
Oretnom23 Simple Cold Storage Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3549 has been rated as problematic.
CVE-2022-3549 allows for unrestricted file upload through the Avatar Handler component, which can lead to security risks.
CVE-2022-3549 affects version 1.0 of the Simple Cold Storage Management System.
To mitigate CVE-2022-3549, it is advisable to restrict file uploads or upgrade to a patched version if available.
The vulnerability in CVE-2022-3549 affects the Avatar Handler component of the system.