CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-26645

Critical · CVSS 9.8

Online Banking System Protect — Unrestricted File Upload leading to Remote Code Execution (RCE)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-434

Description

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

Search profile — drives PoC discovery

Symbols Upload Imagefile upload.php uploadcrafted PHP file
Keywords CVE-2022-26645Online Banking System ProtectRCEunrestricted file uploadPHP file uploadUpload Image functionCWE-434
Versions: v1.0

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z