vendor:
Car Rental Management System
by:
Mehmet Kelepçe / Gais Cyber Security
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Car Rental Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2020
Car Rental Management System 1.0 – Remote Code Execution (Authenticated)
The Car Rental Management System 1.0 is vulnerable to remote code execution. By uploading a malicious PHP file through the 'img' parameter, an attacker can execute arbitrary code on the server.
Mitigation:
The vendor should implement proper input validation and sanitization to prevent arbitrary file uploads. Users are advised to update to a patched version of the software if available.