PT-2021-22287 · Unknown · Online Catering Reservation System

Nu11Secur1Ty

·

Published

2021-08-16

·

Updated

2021-09-21

·

CVE-2021-38758

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Online Catering Reservation System version 1.0
Description The issue is related to a directory traversal vulnerability due to a lack of validation in the index.php file. This allows for potential unauthorized access to sensitive files and directories.
Recommendations For Online Catering Reservation System version 1.0, consider validating user input in the index.php file to prevent directory traversal attacks. As a temporary workaround, restrict access to sensitive files and directories until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38758

Affected Products

Online Catering Reservation System