Arbitrary file upload in Multi Language Pharmacy Management System - #VU62507

 

Arbitrary file upload in Multi Language Pharmacy Management System - #VU62507

Published: April 22, 2022


Vulnerability identifier: #VU62507
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to insufficient validation of file during file upload in the editProductImage.php script. A remote attacker can upload a malicious file and execute it on the server.


Affected software

Multi Language Pharmacy Management System

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins