nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-0943 CVE-2023-0943
MEDIUM
SourceCodester Best POS Management System Image save_settings unrestricted upload
Record summary
CVE-2023-0943 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.
Description
A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler. The manipulation of the argument img with the input ../../shell.php leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-221591.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Best POS Management SystemBrowse SourceCodester / Best POS Management System | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBBest pos Management System v1.0 - Remote Code Execution (RCE) on File UploadExploitDB exploitby Ahmed IsmailNot analyzed1 file
References
3VDB-221591 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.221591 VDB-221591 | SourceCodester Best POS Management System Image save_settings unrestricted uploadvdb entryTechnical description
https://vuldb.com/?id.221591