CVE-2022-40878
HIGHExam Reviewer Management System 1.0 - Authenticated RCE
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-40878. PoCs published by Juli Agarwal.
AI-analyzed exploit summary This exploit demonstrates an authenticated remote code execution (RCE) vulnerability in Exam Reviewer Management System 1.0. The attacker uploads a malicious PHP file disguised as a profile image, which is then executed on the server.
Description
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
Exploits (1)
This exploit demonstrates an authenticated remote code execution (RCE) vulnerability in Exam Reviewer Management System 1.0. The attacker uploads a malicious PHP file disguised as a profile image, which is then executed on the server.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H