First published: Thu Sep 28 2023(Updated: )
Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Credit: help@fluidattacks.com help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Online Book Store Project | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-43740.
The severity of CVE-2023-43740 is critical with a score of 8.8.
Online Book Store Project v1.0 is affected by CVE-2023-43740.
CVE-2023-43740 is an Insecure File Upload vulnerability on the 'image' parameter of the admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution.
To mitigate CVE-2023-43740, it is recommended to apply the necessary patches or updates provided by the software vendor.