PT-2022-12556 · Unknown · Sourcecodester Vehicle Service Management System
P.L. Sanu
·
Published
2022-01-06
·
Updated
2022-01-12
·
CVE-2021-46079
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sourcecodester Vehicle Service Management System version 1.0
Description
An Unrestricted File Upload issue exists, allowing a remote attacker to upload malicious files, which can lead to Html Injection.
Recommendations
For Sourcecodester Vehicle Service Management System version 1.0, consider restricting file uploads to only necessary and validated files to minimize the risk of exploitation. As a temporary workaround, restrict access to file upload functionality until a proper fix is available.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Vehicle Service Management System