PT-2021-21300 · Sourcecodester · Sourcecodester Online Covid Vaccination Scheduler System
Faisalfs10X
·
Published
2021-08-03
·
Updated
2021-08-12
·
CVE-2021-36622
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sourcecodester Online Covid Vaccination Scheduler System version 1.0
Description
The issue allows for Arbitrary File Upload. The admin panel has an upload function for profile photos, accessible at "http://localhost/scheduler/admin/?page=user". An attacker could upload a malicious file, such as
shell.php, by setting the Content-Type to image/png. The attacker can then access the uploaded file, potentially leading to unauthorized access.Recommendations
For Sourcecodester Online Covid Vaccination Scheduler System version 1.0, consider disabling the profile photo upload function in the admin panel until a fix is available. Restrict access to the "http://localhost/scheduler/admin/?page=user" endpoint to minimize the risk of exploitation. Avoid allowing uploads with mismatched
Content-Type headers to prevent malicious file uploads.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Online Covid Vaccination Scheduler System