A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some unknown functionality of the file /Superadmin_Dashboard/process/editemployee_process.php. Such manipulation of the argument employee_file201 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Link | Tags |
---|---|
https://vuldb.com/?id.321345 | vdb entry technical description |
https://vuldb.com/?ctiid.321345 | permissions required signature |
https://vuldb.com/?submit.634757 | third party advisory |
https://github.com/lrjbsyh/CVE_Hunter/issues/5 | issue tracking |
https://github.com/lrjbsyh/CVE_Hunter/issues/5#issue-3322736605 | exploit issue tracking |
https://www.sourcecodester.com/ | product |