### [CVE-2022-4276](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4276) ![](https://img.shields.io/static/v1?label=Product&message=House%20Rental%20System&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-266%20Incorrect%20Privilege%20Assignment%20-%3E%20CWE-284%20Improper%20Access%20Controls%20-%3E%20CWE-434%20Unrestricted%20Upload&color=brighgreen) ### Description A vulnerability was found in House Rental System and classified as critical. Affected by this issue is some unknown functionality of the file tenant-engine.php of the component POST Request Handler. The manipulation of the argument id_photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214772. ### POC #### Reference - https://github.com/nikeshtiwari1/House-Rental-System/issues/8 - https://vuldb.com/?id.214772 #### Github No PoCs found on GitHub currently.