ZeroHour

CVE-2020-27956

PoC
CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
Modified
Description

An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).

Vendors
car rental management system project
Products
car rental management system
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.