Sourcecodester Online Pizza Ordering System v1.0 allows the upload of malicious PHP files resulting in Remote Code Execution (RCE).
References
| Link | Resource |
|---|---|
| https://github.com/Trinity-SYT-SECURITY/arbitrary-file-upload-RCE/blob/main/Online%20Pizza%20Ordering%20System%201.0.md | Exploit Third Party Advisory |
| https://www.exploit-db.com/exploits/51431 | Third Party Advisory VDB Entry |
| https://www.chtsecurity.com/news/8b7ace7d-c5b0-42a9-99b6-8fd0814ed7be | |
| https://www.chtsecurity.com/news/50227a91-34ee-4b2d-9c84-954860488202 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-07-10 16:15
Updated : 2023-08-02 15:15
NVD link : CVE-2023-37151
Mitre link : CVE-2023-37151
JSON object : View
Products Affected
online_pizza_ordering_system_project
- online_pizza_ordering_system
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
