CVE-2023-1722
Summary
| CVE | CVE-2023-1722 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-24 02:15:00 UTC |
| Updated | 2023-06-30 07:31:00 UTC |
| Description | Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Yoga Class Registration System Project | Yoga Class Registration System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Yoga Class Registration System 1.0 - ATO | Advisories | Fluid Attacks | MISC | fluidattacks.com | |
| Yoga Class Registration System in PHP and MySQL Free Source Code | Free Source Code Projects and Tutorials | MISC | www.sourcecodester.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.