First published: Tue Sep 15 2020(Updated: )
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters. An attack uses /Online%20Course%20Registration/my-profile.php with the POST parameter photo.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Online Course Registration | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this File Upload vulnerability in SourceCodester Online Course Registration v1.0 is CVE-2020-23828.
CVE-2020-23828 has a severity rating of critical (9.8).
This vulnerability allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters.
The Online Course Registration v1.0 software by SourceCodester is affected by this vulnerability.
At the moment, there is no known fix for CVE-2020-23828. It is recommended to take precautionary measures such as restricting file uploads and implementing additional security controls.