CVE-2022-41537 The v1.0 of the Tours & Travels Management System had an arbitrary file upload vulnerability.
This issue is rated as critical due to the fact that it could be exploited by hackers to carry out a massive data breach. Furthermore,
CVE-2022-41504 An upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code.
In addition, there are other cross site request forgery, SQL injection, and file upload issues. The following are the high level details of the arbitrary
CVE-2022-42142 Ip/tour/admin/operations/update_settings.php is vulnerable to arbitrary code execution.
An attacker can inject malicious code into update_settings.php to execute any malicious code on the system. An attacker can also inject malicious code
CVE-2022-3552 Upload of file with dangerous type in GitHub repository was allowed before v0.0.1.
At that time, if you try to upload file with a dangerous type, such as .exe, .ps1, .psm1, .py, .js, .css, .md, .md, .markdown, .pdf,
CVE-2022-3368 The Software Updater had a vulnerability that allowed an attacker with write access to the filesystem to escalate their privileges.
Additionally, an insufficient validation of user input in the license validation functionality of the Corporate Server functionality allowed remote attackers with low permissions to trick
Episode
00:00:00
00:00:00