CVE-2022-25094
HIGHHome Owners Collection Management System v1.0 - Remote Code Execution via SystemSettings.php Cover Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-25094. PoCs published by Saud Alenazi.
AI-analyzed exploit summary This exploit demonstrates an authenticated file upload vulnerability in Home Owners Collection Management System 1.0, allowing an attacker to upload a malicious PHP file (cmd.php) via the SystemSettings.php endpoint. The uploaded file acts as a webshell, enabling remote command execution (RCE) when accessed with the 's' parameter.
Description
Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.
Exploits (1)
This exploit demonstrates an authenticated file upload vulnerability in Home Owners Collection Management System 1.0, allowing an attacker to upload a malicious PHP file (cmd.php) via the SystemSettings.php endpoint. The uploaded file acts as a webshell, enabling remote command execution (RCE) when accessed with the 's' parameter.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H