vendor:
Voting System
by:
Richard Jones
7.5
CVSS
HIGH
Authenticated Remote Code Execution
RCE
CWE
Product Name: Voting System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 2004 + XAMPP 7.4.4
2021
Voting System 1.0 – File Upload RCE (Authenticated Remote Code Execution)
This exploit allows an authenticated user to upload a malicious file and execute arbitrary code on the target system.
Mitigation:
Implement proper input validation and file upload restrictions. Regularly update the software to patch any vulnerabilities.