vendor:
POS Codekop
by:
yuyudhn
8.8
CVSS
HIGH
Authenticated Remote Code Execution (RCE)
94
CWE
Product Name: POS Codekop
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: CVE-2023-36348
CPE: a:codekop:pos_codekop:2.0
Platforms Tested: Linux
2023
POS Codekop v2.0 – Authenticated Remote Code Execution (RCE)
The application does not sanitize the filename parameter when sending data to /fungsi/edit/edit.php?gambar=user. An attacker can exploit this issue by uploading a PHP file and accessing it, leading to Remote Code Execution.
Mitigation:
The vendor should sanitize the filename parameter to prevent unauthorized code execution. Users should also ensure they are using the latest version of the software and regularly update it.