CVE-2022-31342
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to delete any file on the server by sending a request to a specific part of the online car wash booking system. The attacker needs to know how to craft the request properly, which means they must have some understanding of how the system works.
Technical Description
Online Car Wash Booking System v1.0 is vulnerable to Delete any file via /ocwbs/classes/Master.php?f=delete_img.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Jun 2, 2022
over 3 years ago
Last Modified
Feb 18, 2026
2 days ago
Vendor
oretnom23
Product
online car wash booking system
Related Vulnerabilities
This vulnerability allows an attacker to inject malicious scripts into the website, which could lead to unauthorized actions or data theft from users who visit the affected page. It can be exploited remotely by manipulating a specific input field without needing any special access or credentials.
This vulnerability allows an attacker to manipulate the online car wash booking system's database, potentially gaining access to sensitive information or altering data. To exploit this, the attacker needs to send specially crafted requests to a specific URL in the system.
This vulnerability allows an attacker to manipulate the database of the online car wash booking system, potentially gaining access to sensitive information or altering data. It can be exploited by sending specially crafted requests to a specific URL, making it critical for anyone using this system to secure it immediately.
This vulnerability allows an attacker to manipulate the database of the online car wash booking system, potentially gaining access to sensitive information or altering data. It requires the attacker to send a specially crafted request to the manage_service.php page with a specific ID parameter.
This vulnerability allows an attacker to manipulate the online car wash booking system's database by injecting harmful SQL code through a specific URL, potentially gaining access to sensitive information or altering data. To exploit this, the attacker needs to access the admin services page with the right parameters, making it critical for system security.