packetstormsecurity.com
http://packetstormsecurity.com/files/172672/Faculty-Evaluation-System-1.0-Shell-Upload.html CVE-2023-33440
HIGHNuclei
Faculty Evaluation System 1.0 - Unauthenticated File Upload
Record summary
CVE-2023-33440 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.
Description source: CVE List
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBFaculty Evaluation System 1.0 - Unauthenticated File UploadExploitDB exploitby URGANNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHFaculty Evaluation System v1.0 - Remote Code ExecutionCVSS 7.2
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
Remediation
Apply the latest security patches and updates provided by the vendor to mitigate this vulnerability.
WeaknessesCWE-434
AuthorsHarsh
Template tagscve2023cvepacketstormfacultyrceintrusivefaculty_evaluation_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:faculty_evaluation_system_project:faculty_evaluation_system:1.0:*:*:*:*:*:*:*
http://packetstormsecurity.com/files/172672/Faculty-Evaluation-System-1.0-Shell-Upload.html https://github.com/F14me7wq/bug_report/blob/main/vendors/oretnom23/faculty-evaluation-system/RCE-1.md https://nvd.nist.gov/vuln/detail/CVE-2023-333440 https://github.com/1337kid/Exploits https://github.com/Alexander-Gan/Exploits
Source: ProjectDiscovery
References
3github.com
https://github.com/F14me7wq/bug_report/blob/main/vendors/oretnom23/faculty-evaluation-system/RCE-1.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-33440