Online Notice Board System v1.0 - Insecure File Upload
CVE-2023-50760

8.8HIGH

Key Information:

Vendor
CVE Published:
4 January 2024

What is CVE-2023-50760?

The Online Notice Board System v1.0 developed by Kashipara is affected by an Insecure File Upload vulnerability located in the 'f' parameter of the user/update_profile_pic.php page. This flaw permits an authenticated attacker to upload malicious files, potentially leading to Remote Code Execution on the server that hosts the application. Such vulnerabilities can expose sensitive data and compromise system integrity, posing significant security risks for users and organizations utilizing the platform.

Affected Version(s)

Online Notice Board System 1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-50760 : Online Notice Board System v1.0 - Insecure File Upload