Record summary

CVE-2023-0943 has a selected CVSS score of 4.7 (medium); EIP currently links 1 catalogued exploit.

Description

A vulnerability, which was classified as problematic, has been found in SourceCodester Best POS Management System 1.0. This issue affects the function save_settings of the file index.php?page=site_settings of the component Image Handler. The manipulation of the argument img with the input ../../shell.php leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-221591.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBBest pos Management System v1.0 - Remote Code Execution (RCE) on File UploadExploitDB exploitby Ahmed IsmailNot analyzed1 file
ExploitDB

PoC details

References

3
VDB-221591 | SourceCodester Best POS Management System Image save_settings unrestricted uploadvdb entryTechnical description
https://vuldb.com/?id.221591