Remote Code Execution Vulnerability in Home Owners Collection Management System by Home Owners
CVE-2022-25094
Key Information:
- Vendor
- CVE Published:
- 26 February 2022
Badges
What is CVE-2022-25094?
The Home Owners Collection Management System version 1.0 is susceptible to a remote code execution vulnerability. This occurs through improper handling of the 'cover' parameter in the SystemSettings.php file, allowing an attacker to execute arbitrary code on the server. This flaw poses significant risks, enabling unauthorized control over affected systems, which may lead to data breaches and other malicious activities.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
23% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
