vendor:
Storage Unit Rental Management System
by:
Fikrat Ghuliev (Ghuliev)
9,8
CVSS
HIGH
Remote Code Execution (RCE)
78
CWE
Product Name: Storage Unit Rental Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu
2021
Storage Unit Rental Management System 1.0 – Remote Code Execution (RCE) (Unauthenticated)
This exploit allows an unauthenticated attacker to execute arbitrary code on the vulnerable Storage Unit Rental Management System 1.0. The attacker can send a malicious request with a crafted payload to the vulnerable application, which will then be executed on the server. The payload is sent as a multipart/form-data request with a filename containing the malicious code.
Mitigation:
The application should be updated to the latest version and all unnecessary features should be disabled. Additionally, the application should be configured to use secure authentication methods and access control mechanisms.