vendor:
Online Learning Management System
by:
Bedri Sertkaya
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Online Learning Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:online_learning_management_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 / WAMP Server
2021
Online Learning Management System 1.0 – RCE (Authenticated)
An authenticated remote code execution vulnerability exists in Online Learning Management System 1.0. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable application. This can allow the attacker to execute arbitrary code on the target system.
Mitigation:
The vendor should patch the vulnerability by implementing proper input validation and authentication checks.