10
CVSSv2

CVE-2021-42669

Published: 05/11/2021 Updated: 29/11/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by all users. By uploading a php webshell containing "<?php system($_GET["cmd"]); ?>" the attacker can execute commands on the web server with - /admin/uploads/php-webshell?cmd=id.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

engineers online portal project engineers online portal -

Vendor Advisories

Check Point Reference: CPAI-2021-2115 Date Published: 28 Feb 2024 Severity: Critical ...

Github Repositories

CVE-2021-42669 - Remote code execution via unrestricted file upload vulnerability in the Engineers online portal system.

CVE-2021-42669 CVE-2021-42669 - Remote code execution via unrestricted file upload vulnerability in the Engineers online portal system Technical description: A unrestricted file upload vulnerability exists in the Engineers Online Portal system An attacker can leverage this vulnerability in order to get a remote code execution on the affected web server Once an avatar gets up

CVE-2021-42669 - Remote code execution via unrestricted file upload vulnerability in the Engineers online portal system.

CVE-2021-42669 CVE-2021-42669 - Remote code execution via unrestricted file upload vulnerability in the Engineers online portal system Technical description: A unrestricted file upload vulnerability exists in the Engineers Online Portal system An attacker can leverage this vulnerability in order to get a remote code execution on the affected web server Once an avatar gets up