CVE-2023-5284Unrestricted File Upload in Engineers Online Portal

Severity
8.8HIGHNVD
CNA6.3
EPSS
0.1%
top 67.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29

Description

A vulnerability classified as critical has been found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file upload_save_student.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240912.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-qj57-gm77-m65m: A vulnerability classified as critical has been found in SourceCodester Engineers Online Portal 12023-09-29
CVEList
SourceCodester Engineers Online Portal upload_save_student.php unrestricted upload2023-09-29
CVE-2023-5284 — Unrestricted File Upload | cvebase