PT-2020-16935 · Sourcecodester · Sourcecodester Online Clothing Store

Published

2020-11-17

·

Updated

2020-12-09

·

CVE-2020-28140

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Online Clothing Store version 1.0
Description The issue concerns an arbitrary file upload via the image upload feature of Products.php. This allows for potential malicious file uploads.
Recommendations For SourceCodester Online Clothing Store version 1.0, consider disabling the image upload feature in Products.php until a patch is available to prevent arbitrary file uploads. Restrict access to the Products.php file to minimize the risk of exploitation. Avoid using the image upload feature in Products.php until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28140

Affected Products

Sourcecodester Online Clothing Store