CVE-2021-37221
HIGHCustomer Relationship Management System - Unrestricted File Upload
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2021-37221. PoCs published by Ishan Saha.
AI-analyzed exploit summary This exploit demonstrates a file upload vulnerability in Customer Relationship Management System (CRM) 1.0, allowing remote code execution by uploading a malicious PHP file disguised as an image. The exploit automates user registration, file upload, and shell interaction.
Description
A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create option, which could let a remote malicious user upload an arbitrary php file. .
Exploits (1)
This exploit demonstrates a file upload vulnerability in Customer Relationship Management System (CRM) 1.0, allowing remote code execution by uploading a malicious PHP file disguised as an image. The exploit automates user registration, file upload, and shell interaction.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H