PT-2021-22296 · Unknown · Simple Water Refilling Station Management System

Published

2021-09-07

·

Updated

2021-09-13

·

CVE-2021-38841

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Water Refilling Station Management System version 1.0
Description The issue allows for Remote Code Execution via the System Logo option on the system info page in classes/SystemSettings.php with an update settings action.
Recommendations For Simple Water Refilling Station Management System version 1.0, consider restricting access to the system info page or disabling the update settings action in classes/SystemSettings.php to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38841

Affected Products

Simple Water Refilling Station Management System