Arbitrary File Upload Vulnerability in Project Worlds Official Car Rental System
CVE-2020-11544

7.2HIGH

Key Information:

Vendor
CVE Published:
6 April 2020

What is CVE-2020-11544?

An arbitrary file upload vulnerability exists in Project Worlds Official Car Rental System 1, allowing an admin user to execute commands on the server. This issue is due to improper validation in the upload functionality on the file-manager page, specifically through the add_cars.php endpoint. Attackers can exploit this flaw to upload malicious executable files without any restrictions, potentially compromising the server's security.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-11544 : Arbitrary File Upload Vulnerability in Project Worlds Official Car Rental System