CVE-2022-30529 Information

Description

File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018 allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/upload.php.

Reference

https://github.com/killmonday/isic.lk-RCE https://github.com/asith-eranga/isic

Share on: