Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-34024. PoCs published by sorabug.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-34024, demonstrating an arbitrary file upload vulnerability in Barangay Management System v1.0. The exploit bypasses file type restrictions by manipulating the Content-Type header to upload a malicious PHP file, leading to remote code execution (RCE).
Description
Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.
Exploits (1)
This repository contains a functional exploit for CVE-2022-34024, demonstrating an arbitrary file upload vulnerability in Barangay Management System v1.0. The exploit bypasses file type restrictions by manipulating the Content-Type header to upload a malicious PHP file, leading to remote code execution (RCE).
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H