First published: Thu Mar 30 2023(Updated: )
A vulnerability classified as critical has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected is an unknown function of the file admin/products/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. VDB-224622 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe Young Entrepreneur E-negosyo System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1734 is classified as a critical vulnerability.
CVE-2023-1734 allows for unrestricted file upload due to improper handling of image arguments in the admin functionality.
To fix CVE-2023-1734, ensure to implement strict validation and sanitization of uploaded files for the affected system.
CVE-2023-1734 affects version 1.0 of the Young Entrepreneur E-Negosyo System.
Exploitation of CVE-2023-1734 could lead to unauthorized access to the system and exposure to malware or other security threats.