PT-2021-16452 · Sourcecodester · Sourcecodester Loan Management System
CVE-2021-25200
·
Published
2021-07-28
·
Updated
2021-08-03
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
SourceCodester Learning Management System version 1.0
Description:
The issue allows attackers to upload arbitrary files, which can lead to the execution of arbitrary code. This is achieved by uploading files to the
student avatar.php script located in the lms directory.Recommendations:
For SourceCodester Learning Management System version 1.0, consider restricting access to the
student avatar.php script until a fix is available, or remove the ability to upload files to this endpoint to prevent exploitation.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Loan Management System