CVE-2023-43740: Online Book Store Project v1.0 - Insecure File Upload
Published Sep 28, 2023
·Updated
Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of adminedit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Affected Software
1 affected component
Projectworlds Online Book Store Project=1.0
Event History
Sep 28, 2023
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-43740.
2
What is the severity of CVE-2023-43740?
The severity of CVE-2023-43740 is critical with a score of 8.8.
3
What software is affected by CVE-2023-43740?
Online Book Store Project v1.0 is affected by CVE-2023-43740.
4
How does CVE-2023-43740 work?
CVE-2023-43740 is an Insecure File Upload vulnerability on the 'image' parameter of the admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution.
5
Are there any mitigation steps for CVE-2023-43740?
To mitigate CVE-2023-43740, it is recommended to apply the necessary patches or updates provided by the software vendor.