PT-2019-18968 · Unknown · Online Store System
Published
2019-10-01
·
Updated
2019-10-07
·
CVE-2019-8291
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Online Store System version 1.0
Description
The issue concerns the delete file.php file in the Online Store System, which fails to verify if a user has administrative rights and does not check for path traversal.
Recommendations
For version 1.0, modify the delete file.php file to include checks for administrative rights and path traversal to prevent unauthorized file deletion.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Store System