Arbitrary File Upload Vulnerability in Zoo Management System by Pushpam
CVE-2022-40925
7.2HIGH
What is CVE-2022-40925?
The Zoo Management System version 1.0 contains a vulnerability that allows attackers to upload arbitrary files through the picture upload feature in the 'save_event' file within the Events module of the system's backend. This flaw can potentially lead to unauthorized code execution and manipulation of the system, posing significant security risks.