SourceCodester Best Church Management Software Unrestricted File Upload Vulnerability

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in SourceCodester Best Church Management Software version 1.0. The issue resides in the file '/admin/app/soulwinning_crud.php', where the 'photo' and 'photo1' arguments can be manipulated to upload files without proper restrictions. This vulnerability can be exploited remotely, and such unrestricted uploads may lead to remote code execution.

Impact

Exploitation of this vulnerability allows for unrestricted file uploads, which could be used to upload malicious files that are executed on the server, potentially leading to remote code execution.

Reproduction

To reproduce this vulnerability, send a POST request to '/admin/app/soulwinning_crud.php' with the 'photo' and 'photo1' fields included in the form data. These fields can be used to upload files, such as PDFs, which could be exploited if the uploaded file is executed as a script.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.