PT-2021-16452 · Sourcecodester · Sourcecodester Loan Management System
Published
2021-07-28
·
Updated
2021-08-03
·
CVE-2021-25200
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SourceCodester Learning Management System version 1.0
Description:
The issue allows attackers to upload arbitrary files, which can lead to the execution of arbitrary code. This is achieved by uploading files to the
student avatar.php script located in the lms directory.Recommendations:
For SourceCodester Learning Management System version 1.0, consider restricting access to the
student avatar.php script until a fix is available, or remove the ability to upload files to this endpoint to prevent exploitation.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Loan Management System