Vulnerabilities > Projectworlds > GYM Management System Project > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-28 CVE-2023-5185 Unrestricted Upload of File with Dangerous Type vulnerability in Projectworlds GYM Management System Project 1.0
Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
network
low complexity
projectworlds CWE-434
8.8