sourcecodester Personnel Property Equipment System
cpe:2.3:a:personnel_property_equipment_system_project:personnel_property_equipment_system:*:*:*:*:*:*:*
- 1.0
A vulnerability allowing arbitrary code execution has been identified in Sourcecodester Personnel Property Equipment System version 1.0. The issue arises from an arbitrary file upload feature in the admin_change_picture.php file, located in the ip/ppes/admin/ directory.
Exploitation of this vulnerability allows for arbitrary code execution on the server where the application is hosted.
To reproduce this vulnerability, log in to the application as a super admin. Navigate to the admin_change_picture.php page. Upload a file through the provided file upload feature, ensuring that the file contains malicious PHP code, such as a PHP shell or a file that executes a command. Once the file is uploaded, it will be stored in the admin/uploads directory. Accessing the uploaded file through the web server will trigger the execution of the embedded code.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.