vendor:
Internship Portal Management System
by:
argenestel
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Internship Portal Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:internship_portal_management_system
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 10
2021
Internship Portal Management System 1.0 – Remote Code Execution Via File Upload (Unauthenticated)
This exploit allows an unauthenticated attacker to upload a malicious PHP shell to the Internship Portal Management System 1.0. The attacker can then execute arbitrary code on the vulnerable system by accessing the uploaded shell.
Mitigation:
Ensure that all user input is properly sanitized and validated before being used in any system operations. Additionally, ensure that all user accounts have strong passwords and that all users are using the latest version of the software.