code-projects Content Management System
cpe:2.3:a:code-projects:content_management_system:*:*:*:*:*:*:*
- 1.0
A critical vulnerability allowing unrestricted file uploads has been identified in Code-Projects Content Management System version 1.0. The issue resides in the Publish News Page component, specifically within the file '/admin/publishnews.php'. The vulnerability can be exploited remotely by manipulating the 'image' argument to upload arbitrary files.
Exploitation of this vulnerability allows for arbitrary file uploads, which could be used to upload malicious scripts or executables that could be executed on the server, potentially leading to a compromise of the server or application.
To reproduce this vulnerability, an authenticated user can navigate to the Publish News Page and select a PHP file, such as 'shell.php', to upload. Intercepting the request and changing the 'content-type' header to a valid image type, like 'image/jpeg', will bypass file type restrictions. Once uploaded, the PHP file will be accessible via the '/allpostpics/' directory, where it can be executed, leading to remote code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.