CVE-2022-41406: Malicious File Upload
Published Oct 11, 2022
·Updated
An arbitrary file upload vulnerability in the /admin/adminpic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Affected Software
1 affected component
Church Management System Project Church Management System=1.0
Event History
Oct 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Oct 12, 2022
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-41406.
2
What is the severity level of CVE-2022-41406?
The severity level of CVE-2022-41406 is high with a value of 7.2.
3
What software is affected by CVE-2022-41406?
Church Management System v1.0 is affected by CVE-2022-41406.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is 434.
5
How can I fix the arbitrary file upload vulnerability in Church Management System v1.0?
To fix the arbitrary file upload vulnerability in Church Management System v1.0, apply the latest patch or upgrade to a fixed version provided by the vendor.