CVE-2023-0257: SourceCodester Online Food Ordering System Menu Form unrestricted upload
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image with the input <?php system($GET['c']); ?> leads to unrestricted upload. The attack can be launched remotely. The identifier VDB-218185 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0257?
CVE-2023-0257 has been declared as critical.
How do I fix CVE-2023-0257?
To fix CVE-2023-0257, it's recommended to update to the latest version of the Online Food Ordering System.
What component is affected by CVE-2023-0257?
CVE-2023-0257 affects the Menu Form functionality of the file /fos/admin/index.php?page=menu.
What versions are affected by CVE-2023-0257?
CVE-2023-0257 specifically affects version 2.0 of the Online Food Ordering System.
What type of vulnerability is CVE-2023-0257?
CVE-2023-0257 is a manipulation vulnerability involving the Image argument.