vendor:
Online Marriage Registration System
by:
Selim Enes 'Enesdex' Karaduman
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: Online Marriage Registration System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 / Xampp Server and Wamp Server
2020
Online Marriage Registration System 1.0 Remote Code Execution
This exploit allows an attacker to execute arbitrary code remotely on the Online Marriage Registration System version 1.0. The vulnerability requires authentication, but the system allows free user registration which is enough to exploit the system.
Mitigation:
The vendor should release a patch to fix this vulnerability. Users are advised to update to the latest version of the software.