vendor:
Home Owners Collection Management System
by:
Saud Alenazi
7.5
CVSS
HIGH
Remote Code Execution (RCE)
CWE
Product Name: Home Owners Collection Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: XAMPP, Linux
2022
Home Owners Collection Management System 1.0 – Remote Code Execution (RCE) (Authenticated)
The Home Owners Collection Management System (HOCMS) version 1.0 is vulnerable to remote code execution. An attacker can exploit this vulnerability by sending a specially crafted request to the SystemSettings.php file. By manipulating the 'name' parameter, an attacker can execute arbitrary code on the server. The vulnerability allows an authenticated attacker to execute system commands on the target server, potentially leading to full compromise of the system.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest patch or update the software to a version that is not affected by this vulnerability.