First published: Fri Jun 23 2023(Updated: )
Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Yoga Class Registration System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1721 is considered a critical vulnerability due to its ability to allow remote command execution on the server.
To fix CVE-2023-1721, ensure that proper validation and sanitization are implemented for thumbnails uploaded by administrators.
CVE-2023-1721 affects users of Yoga Class Registration System version 1.0.
CVE-2023-1721 is categorized as a remote command execution vulnerability.
Yes, exploitation of CVE-2023-1721 can lead to unauthorized access and potential data breaches.