vendor:
Online Computer and Laptop Store
by:
Matisse Beckandt (Backendt)
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: Online Computer and Laptop Store
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2023-1826
CPE: a:sourcecodester:online_computer_and_laptop_store:1.0
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=149168, https://www.infosecmatter.com/nessus-plugin-library/?id=110506, https://www.infosecmatter.com/nessus-plugin-library/?id=44691, https://www.infosecmatter.com/nessus-plugin-library/?id=149041, https://www.infosecmatter.com/nessus-plugin-library/?id=149986, https://www.infosecmatter.com/nessus-plugin-library/?id=50073, https://www.infosecmatter.com/nessus-plugin-library/?id=78150, https://www.infosecmatter.com/nessus-plugin-library/?id=68807, https://www.infosecmatter.com/nessus-plugin-library/?id=138223, https://www.infosecmatter.com/nessus-plugin-library/?id=149987
Platforms Tested: Debian 11.6
2023
Online Computer and Laptop Store 1.0 – Remote Code Execution (RCE)
The application does not sanitize the 'img' parameter when sending data to '/classes/SystemSettings.php?f=update_settings'. An attacker can exploit this issue by uploading a PHP file and accessing it, leading to Remote Code Execution.
Mitigation:
Sanitize the 'img' parameter when sending data to '/classes/SystemSettings.php?f=update_settings'