PT-2023-17033 · Sourcecodester · Sourcecodester Simple/Nice Shopping Cart Script
Enjoy
·
Publicado
2023-03-19
·
Atualizado
2024-05-17
·
CVE-2023-1497
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Simple and Nice Shopping Cart Script version 1.0
Description
A critical issue affects the processing of the file uploaderm.php, where the manipulation of the
submit argument leads to unrestricted upload. The attack can be initiated remotely.Recommendations
For SourceCodester Simple and Nice Shopping Cart Script version 1.0, consider disabling the file uploaderm.php until a patch is available to prevent unrestricted upload. Restrict access to the
submit argument in the file uploaderm.php to minimize the risk of exploitation.Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sourcecodester Simple/Nice Shopping Cart Script