vendor:
Online-Pizza-Ordering-1.0
by:
nu11secur1ty
7.5
CVSS
HIGH
Remote Code Execution (RCE)
CWE
Product Name: Online-Pizza-Ordering-1.0
Affected Version From:
Affected Version To:
Patch Exists:
Related CWE:
CPE:
Platforms Tested:
2023
Online-Pizza-Ordering -1.0 – Remote Code Execution (RCE)
The malicious user can request an account from the administrator of this system. Then he can use this vulnerability to destroy or get access to all accounts of this system, even more, worst than ever. The malicious user can upload a very dangerous file on this server, and he can execute it via shell, this is because he can access the upload function from the administrator account.