Vulnerability Details CVE-2022-41504
An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2022-41504
-
cpe:2.3:a:billing_system_project:billing_system:1.0