vendor:
Beauty-salon
by:
nu11secur1ty
7.5
CVSS
HIGH
Web Shell-File Upload - RCE
CWE
Product Name: Beauty-salon
Affected Version From: Beauty-salon-2022
Affected Version To: Beauty-salon-2022
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2022
Beauty-salon v1.0 – Remote Code Execution (RCE)
The parameter `userimage` from Beauty-salon-2022 suffers from Web Shell-File Upload - RCE. NOTE: The user permissions of this system are not working correctly, and the function is not sanitizing well. The attacker can use an already created account from someone who controls this system and he can upload a very malicious file by using this vulnerability, or more precisely (no sanitizing of function for edit image), for whatever account, then he can execute it from anywhere on the external network.
Mitigation:
Sanitize user input and restrict user permissions.