CVE-2023-5277: SourceCodester Engineers Online Portal student_avatar.php unrestricted upload
A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown processing of the file studentavatar.php. The manipulation of the argument change leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240905 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5277?
The severity of CVE-2023-5277 is critical with a CVSS score of 9.8.
What is the affected software of CVE-2023-5277?
The affected software of CVE-2023-5277 is SourceCodester Engineers Online Portal 1.0.
What is the vulnerability type of CVE-2023-5277?
The vulnerability type of CVE-2023-5277 is unrestricted file upload.
Is CVE-2023-5277 exploitable remotely?
Yes, CVE-2023-5277 can be exploited remotely.
How can I fix CVE-2023-5277?
To fix CVE-2023-5277, apply the latest patches or updates provided by the software vendor.