CVE-2022-40089

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simple_college_website_project:simple_college_website:1.0:*:*:*:*:*:*:*

History

27 May 2025, 15:15

Type Values Removed Values Added
CWE CWE-98

21 Nov 2024, 07:20

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-22 22:15

Updated : 2025-05-27 15:15


NVD link : CVE-2022-40089

Mitre link : CVE-2022-40089

CVE.ORG link : CVE-2022-40089


JSON object : View

Products Affected

simple_college_website_project

  • simple_college_website
CWE
NVD-CWE-Other CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')