Arbitrary File Upload Vulnerability in SourceCodester E-Commerce Website
CVE-2021-25207
9.8CRITICAL
What is CVE-2021-25207?
An arbitrary file upload vulnerability exists in SourceCodester's E-Commerce Website v 1.0, allowing attackers to upload malicious files through the prodViewUpdate.php script. This flaw enables unauthorized file execution, increasing the risk of remote code execution attacks that could compromise the integrity and security of the application. Proper validation and sanitization are crucial to mitigate such vulnerabilities.
