CVE-2019-18417: Malicious File Upload
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18417?
CVE-2019-18417 is a vulnerability in Sourcecodester Restaurant Management System 1.0 that allows an authenticated attacker to upload arbitrary files resulting in code execution.
How severe is CVE-2019-18417?
CVE-2019-18417 has a severity rating of 8.8 (high).
How does CVE-2019-18417 occur?
CVE-2019-18417 occurs because the application fails to adequately sanitize user-supplied input when adding a new food, allowing the upload of arbitrary (potentially malicious) files.
What is the affected software version of CVE-2019-18417?
Sourcecodester Restaurant Management System 1.0 is the affected software version of CVE-2019-18417.
Is there a reference for CVE-2019-18417?
Yes, you can refer to the following link for more information: [https://www.sevenlayers.com/index.php/265-restaurant-management-system-1-0-arbitrary-file-upload](https://www.sevenlayers.com/index.php/265-restaurant-management-system-1-0-arbitrary-file-upload)