vendor:
Human Resource Information System Using PHP
by:
Reza Afsahi
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Human Resource Information System Using PHP
Affected Version From: 0.1
Affected Version To: 0.1
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:sourcecodester:human_resource_information_system_using_php:0.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: PHP 7.4.11, Linux x64_x86
2021
Human Resource Information System 0.1 – Remote Code Execution (Unauthenticated)
The web application allows for an unauthenticated file upload which can result in a Remote Code Execution.
Mitigation:
Implement authentication and authorization checks for file uploads.