A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://vuldb.com/?id.296577 | vdb entry permissions required |
https://vuldb.com/?ctiid.296577 | signature vdb entry permissions required |
https://vuldb.com/?submit.505212 | third party advisory vdb entry |
https://www.sourcecodester.com/ | product |