vendor:
Online Railway Reservation System
by:
Zachary Asher
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: Online Railway Reservation System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:online_railway_reservation_system:1.0
Platforms Tested: Online Railway Reservation System 1.0
2022
Online Railway Reservation System 1.0 – Remote Code Execution (RCE) (Unauthenticated)
A vulnerability exists in the Online Railway Reservation System 1.0, which allows an unauthenticated attacker to execute arbitrary code on the vulnerable system. This is achieved by sending a malicious POST request to the SystemSettings.php file, which contains a payload that is executed by the vulnerable system. The attacker can then view the output of the command by sending a GET request to the orrs/ directory.
Mitigation:
The vendor should patch the vulnerability by properly validating user input and sanitizing the data before executing it.