CVE-2021-28294: Malicious File Upload
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28294?
CVE-2021-28294 is categorized as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2021-28294?
To mitigate CVE-2021-28294, you should implement file upload validation and restrict allowed file types on the affected PHP script.
What systems are affected by CVE-2021-28294?
CVE-2021-28294 specifically affects Online Ordering System version 1.0.
Can CVE-2021-28294 lead to a complete system compromise?
Yes, exploitation of CVE-2021-28294 can lead to remote code execution, potentially allowing an attacker to fully compromise the system.
What actions should I take if I have experienced a breach due to CVE-2021-28294?
If you suspect a breach due to CVE-2021-28294, you should immediately isolate the affected system, perform a thorough investigation, and apply necessary security patches.