ZeroHour

CVE-2020-28130

PoC
CVSS 3.1
9.8 critical
EPSS
7%p93
Published
()
Modified
Description

An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

Vendors
online library management system project
Products
online library management system
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.