Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .
References
Link | Resource |
---|---|
https://www.exploit-db.com/exploits/50308 | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-10-29 10:15
Updated : 2021-11-02 11:28
NVD link : CVE-2021-41645
Mitre link : CVE-2021-41645
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
budget_and_expense_tracker_system_project
- budget_and_expense_tracker_system