Code-Projects Mobile Shop Management System File Upload Vulnerability
Vulnerability
A file upload vulnerability has been identified in Code-Projects Mobile Shop Management System version 1.0. The issue resides in the ExAddProduct.php file, where uploaded files are not properly validated. This flaw allows arbitrary files, including PHP scripts, to be uploaded and executed.
Impact
Exploitation of this vulnerability could lead to unauthorized file uploads, allowing attackers to upload and execute malicious PHP files on the server.
Reproduction
To reproduce this vulnerability, upload a file through the 'ProductImage' field in the ExAddProduct.php file. The uploaded file is not properly checked for its type or extension, allowing PHP files to be uploaded. Once uploaded, the file can be executed, potentially leading to a server compromise.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
