A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222978 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://blog.csdn.net/Dwayne_Wade/article/details/129526901 | Broken Link |
https://vuldb.com/?ctiid.222978 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.222978 | Permissions Required Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Mar 2023, 15:33
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:a:online_tours_\&_travels_management_system_project:online_tours_\&_travels_management_system:1.0:*:*:*:*:*:*:* | |
References | (MISC) https://blog.csdn.net/Dwayne_Wade/article/details/129526901 - Broken Link | |
References | (MISC) https://vuldb.com/?ctiid.222978 - Permissions Required, Third Party Advisory | |
References | (MISC) https://vuldb.com/?id.222978 - Permissions Required, Third Party Advisory |
14 Mar 2023, 16:55
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-14 15:15
Updated : 2024-05-17 02:18
NVD link : CVE-2023-1391
Mitre link : CVE-2023-1391
CVE.ORG link : CVE-2023-1391
JSON object : View
Products Affected
online_tours_\&_travels_management_system_project
- online_tours_\&_travels_management_system
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type