PT-2019-18968 · Unknown · Online Store System
Publicado
2019-10-01
·
Atualizado
2019-10-07
·
CVE-2019-8291
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Online Store System version 1.0
Description
The issue concerns the delete file.php file in the Online Store System, which fails to verify if a user has administrative rights and does not check for path traversal.
Recommendations
For version 1.0, modify the delete file.php file to include checks for administrative rights and path traversal to prevent unauthorized file deletion.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Online Store System