Online Notice Board System v1.0 - File UL
8.8
High
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Online Notice Board System v1.0 - Insecure File Upload
Code name
State
Public
Release date
Jan 3, 2024
Affected product
Online Notice Board System
Vendor
Kashipara Group
Affected version(s)
Version 1.0
Vulnerability name
Insecure File Upload
Vulnerability type
Remotely exploitable
Yes
CVSS v3.0 vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0 base score
8.8
Exploit available
Yes
CVE ID(s)
Description
Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Vulnerability
The 'f' parameter of the user/update_profile_pic.php page resource does not validate the contents, extension and type of the file uploaded as a book image, leading to an arbitrary file upload which can be abused to obtain Remote Code Execution. The vulnerable code is located at profile/i.php page:
Our security policy
We have reserved the ID CVE-2023-50760 to refer to this issue from now on.
System Information
Version: Online Notice Board System v1.0
Operating System: Any
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://www.kashipara.com/
Timeline
Vulnerability discovered
Jan 3, 2024
Vendor contacted
Jan 3, 2024
Public disclosure
Jan 3, 2024