Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-39179

Description

College Management System v1.0 - Authenticated remote code execution.An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload.php file that contains malicious code via student.php file.

POC

Reference

- https://www.gov.il/en/Departments/faq/cve_advisories

Github

No PoCs found on GitHub currently.