First published: Wed Oct 28 2020(Updated: )
An Arbitrary File Upload in the Upload Image component in SourceCodester Car Rental Management System 1.0 allows the user to conduct remote code execution via admin/index.php?page=manage_car because .php files can be uploaded to admin/assets/uploads/ (under the web root).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Car Rental Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-27956.
The severity of CVE-2020-27956 is critical, with a severity value of 9.8.
The affected software of CVE-2020-27956 is Car Rental Management System 1.0 by Car Rental Management System Project.
CVE-2020-27956 allows remote code execution by exploiting an arbitrary file upload vulnerability in the Upload Image component in SourceCodester Car Rental Management System 1.0.
Yes, there are available exploits for CVE-2020-27956. Please refer to the following references for more information: [ExploitDB](https://www.exploit-db.com/exploits/48931) and [SourceCodester](https://www.sourcecodester.com/php/14544/car-rental-management-system-using-phpmysqli-source-code.html).