CVE-2022-40925 — Unrestricted File Upload in ZOO Management System

Severity
7.2HIGHNVD
EPSS
0.4%
top 36.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 26
Latest updateSep 27

Description

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-v23c-hwjc-8qrh: Zoo Management System v1↗2022-09-27
â–¶
CVEList
CVE-2022-40925: Zoo Management System v1↗2022-09-26
â–¶
CVE-2022-40925 — Unrestricted File Upload | cvebase