Arbitrary File Upload Vulnerability in Project Worlds Official Car Rental System
CVE-2020-11544
7.2HIGH
What is CVE-2020-11544?
An arbitrary file upload vulnerability exists in Project Worlds Official Car Rental System 1, allowing an admin user to execute commands on the server. This issue is due to improper validation in the upload functionality on the file-manager page, specifically through the add_cars.php endpoint. Attackers can exploit this flaw to upload malicious executable files without any restrictions, potentially compromising the server's security.