College Management System v1.0 - Authenticated remote code execution.
An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload
.php file that contains malicious code via student.php file.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.gov.il/en/Departments/faq/cve_advisories |
![]() ![]() |
History
Mon, 28 Apr 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: INCD
Published: 2022-11-17T22:27:55.603Z
Updated: 2025-04-28T18:14:25.817Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39179

Updated: 2024-08-03T12:00:42.476Z

Status : Modified
Published: 2022-11-17T23:15:18.490
Modified: 2025-04-28T19:15:45.357
Link: CVE-2022-39179

No data.