CVE-2021-41643
CRITICALChurch Management System 1.0 - Remote Code Execution via Image Upload Field
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-41643. PoCs published by Abdullah Khawaja, hax3xploit.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated file upload vulnerability in Church Management System 1.0, allowing remote code execution by bypassing image upload filters. It uploads a PHP shell and establishes a webshell for command execution.
Description
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.
Exploits (2)
This exploit demonstrates an unauthenticated file upload vulnerability in Church Management System 1.0, allowing remote code execution by bypassing image upload filters. It uploads a PHP shell and establishes a webshell for command execution.
This exploit leverages an unauthenticated file upload vulnerability in Church Management System 1.0 to achieve remote code execution (RCE) by uploading a malicious PHP shell. The exploit bypasses image upload filters and provides an interactive webshell for command execution.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H