CVE-2023-30122: Malicious File Upload
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=savemenu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30122?
CVE-2023-30122 is an arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 that allows attackers to execute arbitrary code via uploading a crafted PHP file.
How do attackers exploit CVE-2023-30122?
Attackers exploit CVE-2023-30122 by uploading a crafted PHP file using the component /admin/ajax.php?action=save_menu, which allows them to execute arbitrary code.
What is the severity of CVE-2023-30122?
CVE-2023-30122 has a severity rating of critical with a score of 9.8 out of 10.
What software is affected by CVE-2023-30122?
The Online Food Ordering System v2.0 is affected by CVE-2023-30122.
How can I fix CVE-2023-30122?
To fix CVE-2023-30122, it is recommended to apply the latest security patches and updates provided by the Online Food Ordering System Project to address the arbitrary file upload vulnerability.