CVE-2022-1837
Home Clean Services Management System unrestricted upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Home Clean Services Management System 1.0. It has been rated as critical. Affected by this issue is register.php?link=registerand. The manipulation with the input <?php phpinfo();?> leads to code execution. The attack may be launched remotely but demands an authentication. Exploit details have been disclosed to the public.
Se ha encontrado una vulnerabilidad en Home Clean Services Management System versión 1.0. Ha sido calificado como crítica. El problema afecta a register.php?link=registerand. La manipulación con la entrada (?php phpinfo();?) conlleva a una ejecución de código. El ataque puede lanzarse de forma remota pero exige una autenticación. Los detalles de la explotación han sido divulgados al público
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-24 CVE Reserved
- 2022-05-24 CVE Published
- 2023-12-15 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.200582 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/Xor-Gerke/webray.com.cn/blob/main/cve/Home%20Clean%20Services%20Management%20System/HCS_add_register.php_File_Upload_Getshell.md | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Home Clean Services Management System Project Search vendor "Home Clean Services Management System Project" | Home Clean Services Management System Search vendor "Home Clean Services Management System Project" for product "Home Clean Services Management System" | 1.0 Search vendor "Home Clean Services Management System Project" for product "Home Clean Services Management System" and version "1.0" | - |
Affected
|