PT-2021-23363 · Sourcecodester · Sourcecodester Online Food Ordering System
Published
2021-10-29
·
Updated
2021-11-02
·
CVE-2021-41644
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sourcecodester Online Food Ordering System version 2.0
Description
A Remote Code Execution (RCE) issue exists due to a maliciously crafted PHP file that bypasses the image upload filters, allowing for potential code execution.
Recommendations
For version 2.0, consider disabling the image upload feature until a patch is available to prevent exploitation of this issue. Restrict access to the upload module to minimize the risk of RCE. Avoid using the image upload functionality in the affected system until the issue is resolved.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Online Food Ordering System