First published: Fri Nov 16 2018(Updated: )
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
School Event Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18793 has been classified as a medium severity vulnerability due to its potential for arbitrary file upload.
To fix CVE-2018-18793, ensure that file upload functionality is secured by implementing strict validation and sanitization of uploaded files.
The risks associated with CVE-2018-18793 include the potential for attackers to upload malicious files, which could lead to unauthorized access or server compromise.
CVE-2018-18793 affects version 1.0 of the School Event Management System.
Yes, CVE-2018-18793 can be exploited remotely if the affected software is accessible over the internet.