ID:8156 - Exploit for Arbitrary file upload in School ERP Pro - CVE-2022-32119

 
Main Vulnerability Database Exploits ID:8156 - Exploit for Arbitrary file upload in School ERP Pro - CVE-2022-32119

ID:8156 - Exploit for Arbitrary file upload in School ERP Pro - CVE-2022-32119

Published: July 20, 2022


Vulnerability identifier: #VU65433
Vulnerability risk: Medium
CVE-ID: CVE-2022-32119
CWE-ID: CWE-434
Exploitation vector: Remote access
Vulnerable software:
School ERP Pro

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload by the Add Photo function in the photogalleries.inc.php script and the import staff excel function in the 1finance_master.inc.php script. A remote user can upload a malicious file and execute it on the server.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.