CVE-2021-41644: Malicious File Upload
Published Oct 29, 2021
·Updated
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
Affected Software
2 affected components
Online Food Ordering System Project Online Food Ordering System=2.0
oretnom23 Online Food Ordering System=2.0
Event History
Oct 29, 2021
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-41644?
CVE-2021-41644 is a Remote Code Execution (RCE) vulnerability in Sourcecodester Online Food Ordering System 2.0.
2
How does CVE-2021-41644 work?
CVE-2021-41644 allows an attacker to execute arbitrary code on the system by uploading a malicious PHP file that bypasses the image upload filters.
3
What is the severity of CVE-2021-41644?
CVE-2021-41644 has a severity rating of critical (9.8).
4
Which software versions are affected by CVE-2021-41644?
Online Food Ordering System 2.0 is affected by CVE-2021-41644.
5
How can I fix CVE-2021-41644?
To fix CVE-2021-41644, it is recommended to install the latest patched version of Online Food Ordering System and ensure that image upload filters are properly implemented.