code-projects/Fabian Ros Library Management System
cpe:2.3:a:fabianros:library_management_system:*:*:*:*:*:*:*
- 2.0
This vulnerability is being actively exploited in the wild.
A critical vulnerability allowing unrestricted file uploads has been identified in Code-Projects Fabian Ros Library Management System version 2.0. The issue arises in the file admin/profile_update.php, where the photo parameter is not properly sanitized, enabling arbitrary file uploads. This vulnerability can be exploited remotely.
Exploitation of this vulnerability could lead to arbitrary file uploads, which may allow attackers to upload malicious files that could be executed on the server or used to compromise the application.
To reproduce this vulnerability, send a request to the admin/profile_update.php file with an unsanitized photo parameter. This can be done by manipulating the upload request to include a file that exploits the unrestricted upload capability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.