CVE-2020-10224: Malicious File Upload
An unauthenticated file upload vulnerability has been identified in adminadd.php in PHPGurukul Online Book Store 1.0. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to the server, including PHP files, which could result in command execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10224?
CVE-2020-10224 is an unauthenticated file upload vulnerability in PHPGurukul Online Book Store 1.0.
How can an attacker exploit CVE-2020-10224?
An unauthenticated remote attacker could exploit CVE-2020-10224 to upload content to the server, including PHP files, which could result in command execution.
Is CVE-2020-10224 a critical vulnerability?
Yes, CVE-2020-10224 has a severity rating of 9.8 (critical).
How can I fix CVE-2020-10224?
To fix CVE-2020-10224, update the PHPGurukul Online Book Store to a version that has a patch for the vulnerability.
What is CWE-434?
CWE-434 refers to unrestricted upload of file with dangerous type, which is the vulnerability category for CVE-2020-10224.