In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.sourcecodester.com/php/12802/php-staff-id-card-creation-and-printing-system.html | third party advisory |
https://www.exploit-db.com/exploits/49877 | third party advisory vdb entry exploit |