Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-54291
HistoryJun 09, 2022 - 12:00 a.m.

Wedding Management System Arbitrary File Upload Vulnerability (CNVD-2022-54291)

2022-06-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
wedding management system
arbitrary file upload
validation
uploaded files
photos edit
remote code execution
john paul lim gabule

EPSS

0.001

Percentile

42.9%

Wedding Management System v1.0 is a wedding planning management system by John Paul Lim Gabule, a personal developer. The vulnerability is caused by a lack of validation of the uploaded files in the photos_edit.php page, which could be exploited to upload malicious files and remotely execute arbitrary code.

EPSS

0.001

Percentile

42.9%

Related for CNVD-2022-54291