CVE-2022-3492

A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerability affects unknown code of the component Profile Photo Handler. The manipulation of the argument parameter leads to os command injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-210772.
References
Link Resource
https://vuldb.com/?id.210772 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:human_resource_management_system_project:human_resource_management_system:1.0:*:*:*:*:*:*:*

Information

Published : 2022-10-13 09:15

Updated : 2022-10-14 07:38


NVD link : CVE-2022-3492

Mitre link : CVE-2022-3492


JSON object : View

CWE
CWE-707

Improper Neutralization

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Advertisement

dedicated server usa

Products Affected

human_resource_management_system_project

  • human_resource_management_system