blog.csdn.netexploit
https://blog.csdn.net/Dwayne_Wade/article/details/129526901 CVE-2023-1391
MEDIUM
SourceCodester Online Tours & Travels Management System ab.php unrestricted upload
Record summary
CVE-2023-1391 has a selected CVSS score of 4.7 (medium).
Description
A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222978 is the identifier assigned to this vulnerability.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Online Tours & Travels Management SystemBrowse SourceCodester / Online Tours & Travels Management System | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-1391 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.222978 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.222978