ZeroHour

CVE-2019-18417

PoC
CVSS 3.1
8.8 high
EPSS
2%p76
Published
()
Modified
Description

Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.

Vendors
sourcecodester
Products
restaurant management system
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.