CVE-2023-1722 describes a critical remote code execution vulnerability in the Yoga Class Registration System version 1.0. This flaw allows an authenticated administrator to execute arbitrary commands on the server due to insufficient validation of uploaded class thumbnails. With a CVSS score of 8.8 (High), successful exploitation could lead to complete compromise of the affected system, including data confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or active exploitation have been observed, the high severity warrants immediate patching for affected yoga_class_registration_system_project and yoga_class_registration_system instances.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:yoga_class_registration_system_project:yoga_class_registration_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.