Remote Code Execution can occur in Simple Water Refilling Station Management System 1.0 via the System Logo option on the system_info page in classes/SystemSettings.php with an update_settings action.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.sourcecodester.com/php/14906/simple-water-refilling-station-management-system-php-free-source-code.html | third party advisory product |
https://www.sourcecodester.com/users/tips23 | third party advisory |
https://www.exploit-db.com/exploits/50205 | exploit vdb entry third party advisory |