PT-2021-21300 · Sourcecodester · Sourcecodester Online Covid Vaccination Scheduler System

Faisalfs10X

·

Published

2021-08-03

·

Updated

2021-08-12

·

CVE-2021-36622

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Online Covid Vaccination Scheduler System version 1.0
Description The issue allows for Arbitrary File Upload. The admin panel has an upload function for profile photos, accessible at "http://localhost/scheduler/admin/?page=user". An attacker could upload a malicious file, such as shell.php, by setting the Content-Type to image/png. The attacker can then access the uploaded file, potentially leading to unauthorized access.
Recommendations For Sourcecodester Online Covid Vaccination Scheduler System version 1.0, consider disabling the profile photo upload function in the admin panel until a fix is available. Restrict access to the "http://localhost/scheduler/admin/?page=user" endpoint to minimize the risk of exploitation. Avoid allowing uploads with mismatched Content-Type headers to prevent malicious file uploads.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36622

Affected Products

Sourcecodester Online Covid Vaccination Scheduler System