Security Advisory

CVE-2019-18417

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-10-24 17:30:14
Last updated 2024-08-05 01:54:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.