PT-2020-16918 · Sourcecodester · Sourcecodester Alumni Management System
Published
2020-12-15
·
Updated
2020-12-17
·
CVE-2020-28072
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DourceCodester Alumni Management System version 1.0
Description
A Remote Code Execution issue exists, allowing an authenticated attacker to upload arbitrary files in the "gallery.php" page and execute them on the server. This enables the attacker to achieve Remote Code Execution (RCE).
Recommendations
For DourceCodester Alumni Management System version 1.0, consider restricting access to the "gallery.php" page to prevent arbitrary file uploads until a fix is available. As a temporary workaround, disabling the file upload functionality in the gallery.php page can help minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Alumni Management System