Online Book Store Project v1.0 - Insecure File Upload
9.1
Critical
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Online Book Store Project v1.0 - Insecure File Upload
Code name
State
Public
Release date
Sep 28, 2023
Affected product
Online Book Store Project
Affected version(s)
Version 1.0
Vulnerability name
Insecure File Upload
Vulnerability type
Remotely exploitable
Yes
CVSS v3.1 vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v3.1 base score
9.1
Exploit available
Yes
CVE ID(s)
Description
Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Vulnerability
The 'image' parameter of the admin_edit.php resource does not validate the contents, extension and type of the file uploaded as a book image, leading to an arbitrary file upload which can be abused to obtain Remote Code Execution. The vulnerable code is located at edit_book.php:
Evidence of exploitation

Our security policy
We have reserved the ID CVE-2023-43740 to refer to this issue from now on. Disclosure policy
System Information
Version: Online Book Store Project v1.0
Operating System: Any
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://projectworlds.in/
Timeline
Vulnerability discovered
Sep 21, 2023
Vendor contacted
Sep 21, 2023
Public disclosure
Sep 28, 2023