Arbitrary File Upload in Home Owners Collection Management System by Lohyt
CVE-2022-25016
9.8CRITICAL
Key Information:
- Vendor
- CVE Published:
- 2 March 2022
What is CVE-2022-25016?
The Home Owners Collection Management System v1.0 is vulnerable to an arbitrary file upload flaw through the component /student_attendance/index.php. This security issue permits attackers to upload malicious PHP files, which can then be executed to gain unauthorized access and potentially control the server.
