VulnerabilityModified
CVE-2019-18417
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution.
HIGH 8.8EPSS 1.73%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.73% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- sourcecodester/restaurant management system
- Source
- cve@mitre.org
References
- https://www.sevenlayers.com/index.php/265-restaurant-management-system-1-0-arbitrary-file-uploadExploit, Third Party Advisory
- https://www.sevenlayers.com/index.php/265-restaurant-management-system-1-0-arbitrary-file-uploadExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.