CVE-2023-1722: Yoga Class Registration System 1.0 - ATO

9.1 CVSS

Description

Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

Classification

CVE ID: CVE-2023-1722

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.1

Affected Products

Vendor: Yoga Class Registration System

Product: Yoga Class Registration System

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.23% (probability of being exploited)

EPSS Percentile: 61.32% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://fluidattacks.com/advisories/wyckoff/
https://www.sourcecodester.com/php/16097/yoga-class-registration-system-php-and-mysql-free-source-code.html

Timeline