Unrestricted Photo Upload Vulnerability in Online Food Ordering System
CVE-2024-7189
Key Information:
- Vendor
- Itsourcecode
- Vendor
- CVE Published:
- 29 July 2024
Badges
Summary
A vulnerability has been identified in the itsourcecode Online Food Ordering System version 1.0, specifically in the script editproduct.php. This issue allows for unrestricted file uploads due to improper validation of the 'photo' argument. Attackers can exploit this vulnerability remotely, potentially enabling them to upload malicious files to the server. The public disclosure of this exploit increases the urgency for affected users to address the security implications associated with this vulnerability.
Affected Version(s)
Online Food Ordering System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved