PT-2023-16629 · Sourcecodester · Sourcecodester Best Pos Management System

Mroz1L

·

Published

2023-02-21

·

Updated

2024-05-17

·

CVE-2023-0943

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Best POS Management System version 1.0
Description A problematic issue has been found in the Image Handler component, affecting the function save settings of the file "index.php?page=site settings". The manipulation of the argument img with the input ../../shell.php leads to unrestricted upload. The attack can be initiated remotely.
Recommendations For SourceCodester Best POS Management System version 1.0, consider disabling the save settings function in the "index.php?page=site settings" file until a patch is available. Restrict access to the Image Handler component to minimize the risk of exploitation. Avoid using the img argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-0943

Affected Products

Sourcecodester Best Pos Management System