CVE-2022-3458

CVE-2022-3458

A vulnerability has been found in SourceCodester Human Resource Management System 1.0 (Asset Management Software) and classified as critical. Affected by this vulnerability is some unknown processing of the file /employeeview.php of the component Image File Handler. The manipulation with an unknown input leads to a unrestricted upload vulnerability. The CWE definition for the vulnerability is CWE-434. The product allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product’s environment. As an impact it is known to affect confidentiality, integrity, and availability.

The bug was discovered 11/10/2022. The weakness was shared 10/11/2022 by Akash Pandey (l3v1ath0n). This vulnerability is known as CVE-2022-3458. Technical details of the vulnerability are known, but there is no available exploit. The attack technique deployed by this issue is T1608.002 according to MITRE ATT&CK.

By approaching the search of inurl:employeeview.php it is possible to find vulnerable targets with Google Hacking.

There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.

Source: https://vuldb.com/?id.210559

 

Stay ahead of the cybersecurity curve!

Sign up now to receive our newsletter and stay informed about the latest trends and insights. Don’t miss out on cybersecurity updates! 

ByteArmor is a firm that focuses on maximizing the cybersecurity posture and improve the IT project management capabilities of your organization.