CVE-2022-2746 is a critical unrestricted file upload vulnerability affecting the Admin_add.php file in SourceCodester Simple Online Book Store System. With a CVSS score of 9.8, this vulnerability allows unauthenticated remote attackers to upload arbitrary files, potentially leading to full system compromise (CWE-434). While no public exploit code or active exploitation has been confirmed, its high FAUCET Risk Score of 92/100 and mention in a CISA advisory highlight its significant potential impact. The vulnerability has garnered minimal community discussion and no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:simple_online_book_store_system_project:simple_online_book_store_system:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.