PT-2020-16918 · Sourcecodester · Sourcecodester Alumni Management System

Published

2020-12-15

·

Updated

2020-12-17

·

CVE-2020-28072

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DourceCodester Alumni Management System version 1.0
Description A Remote Code Execution issue exists, allowing an authenticated attacker to upload arbitrary files in the "gallery.php" page and execute them on the server. This enables the attacker to achieve Remote Code Execution (RCE).
Recommendations For DourceCodester Alumni Management System version 1.0, consider restricting access to the "gallery.php" page to prevent arbitrary file uploads until a fix is available. As a temporary workaround, disabling the file upload functionality in the gallery.php page can help minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28072

Affected Products

Sourcecodester Alumni Management System