College Management System v1.0 - Authenticated remote code execution.
An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload
.php file that contains malicious code via student.php file.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.gov.il/en/Departments/faq/cve_advisories |
|
History
Mon, 28 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCD
Published: 2022-11-17T22:27:55.603Z
Updated: 2025-04-28T18:14:25.817Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39179
Updated: 2024-08-03T12:00:42.476Z
Status : Modified
Published: 2022-11-17T23:15:18.490
Modified: 2025-04-28T19:15:45.357
Link: CVE-2022-39179
No data.