vendor:
Online Leave Management System
by:
Justin White
8,8
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: Online Leave Management System
Affected Version From: V1
Affected Version To: V1
Patch Exists: NO
Related CWE: None
CPE: a:sourcecodester:online_leave_management_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2021
Online Leave Management System 1.0 – Arbitrary File Upload to Shell (Unauthenticated)
This exploit allows an unauthenticated attacker to upload a malicious file to the target system. The malicious file contains a reverse shell payload which can be used to gain access to the target system. The exploit is tested on Linux.
Mitigation:
Ensure that the application is configured to only allow the upload of files with the appropriate file extensions and that the application is configured to only allow the upload of files with the appropriate file size.