Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-14T03:14:22

Updated: 2022-09-14T03:14:22

Reserved: 2022-07-25T00:00:00


Link: CVE-2022-36667

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-14T11:15:49.723

Modified: 2022-09-16T03:00:33.397


Link: CVE-2022-36667

JSON object: View

cve-icon Redhat Information

No data.

CWE