Vulnerability Description
An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Online Bike Rental Project | Online Bike Rental | 1.0 |
Related Weaknesses (CWE)
References
- https://packetstormsecurity.com/files/158704/Online-Bike-Rental-1.0-Shell-UploadThird Party AdvisoryVDB Entry
- https://www.sourcecodester.com/php/14374/online-bike-rental-phpmysql.htmlProduct
- https://packetstormsecurity.com/files/158704/Online-Bike-Rental-1.0-Shell-UploadThird Party AdvisoryVDB Entry
- https://www.sourcecodester.com/php/14374/online-bike-rental-phpmysql.htmlProduct
FAQ
What is CVE-2020-24195?
CVE-2020-24195 is a vulnerability with a CVSS score of 9.1 (CRITICAL). An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
How severe is CVE-2020-24195?
CVE-2020-24195 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-24195?
Check the references section above for vendor advisories and patch information. Affected products include: Online Bike Rental Project Online Bike Rental.