CVE-2023-43740

Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
References
Link Resource
https://fluidattacks.com/advisories/shagrath Exploit Third Party Advisory
https://projectworlds.in/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:projectworlds:online_book_store_project:1.0:*:*:*:*:*:*:*

History

02 Oct 2023, 12:47

Type Values Removed Values Added
CPE cpe:2.3:a:projectworlds:online_book_store_project:1.0:*:*:*:*:*:*:*
First Time Projectworlds online Book Store Project
Projectworlds
CWE CWE-434
References (MISC) https://fluidattacks.com/advisories/shagrath - (MISC) https://fluidattacks.com/advisories/shagrath - Exploit, Third Party Advisory
References (MISC) https://projectworlds.in/ - (MISC) https://projectworlds.in/ - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

29 Sep 2023, 15:15

Type Values Removed Values Added
Summary [PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to [IMPACT] via [VECTOR] Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

28 Sep 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-28 21:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-43740

Mitre link : CVE-2023-43740

CVE.ORG link : CVE-2023-43740


JSON object : View

Products Affected

projectworlds

  • online_book_store_project
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type