PT-2021-23363 · Sourcecodester · Sourcecodester Online Food Ordering System

Published

2021-10-29

·

Updated

2021-11-02

·

CVE-2021-41644

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Online Food Ordering System version 2.0
Description A Remote Code Execution (RCE) issue exists due to a maliciously crafted PHP file that bypasses the image upload filters, allowing for potential code execution.
Recommendations For version 2.0, consider disabling the image upload feature until a patch is available to prevent exploitation of this issue. Restrict access to the upload module to minimize the risk of RCE. Avoid using the image upload functionality in the affected system until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41644

Affected Products

Sourcecodester Online Food Ordering System