Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rmccarth

#29966of 53,625
8.8Total CVSS
Vulnerabilities · 1
PT-2021-19456
8.8
2021-01-20
Unknown · Churchrota · CVE-2021-3164
**Name of the Vulnerable Software and Affected Versions** ChurchRota version 2.6.4 **Description** The issue allows for authenticated remote code execution. It is possible to upload and execute an arbitrary file without needing file upload permission, by sending a POST request to the "resources.php" API endpoint. **Recommendations** For ChurchRota version 2.6.4, consider restricting access to the "resources.php" endpoint until a fix is available. As a temporary workaround, limit the ability to upload files to only necessary users to minimize the risk of exploitation.