Beveiligingsadvies

CVE-2021-36622

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-08-03 17:42:11
Laatst bijgewerkt 2024-08-04 01:01:58
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as shell.php with the Content-Type: image/png. Then, the attacker have to visit the uploaded profile photo to access the shell.