Online Notice Board System v1.0 - File UL
8,8
High
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Online Notice Board System v1.0 - Insecure File Upload
Code name
State
Public
Release date
3 ene 2024
Affected product
Online Notice Board System
Vendor
Kashipara Group
Affected version(s)
Version 1.0
Vulnerability name
Insecure File Upload
Vulnerability type
Remotely exploitable
Yes
CVSS v3.0 vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.0 base score
8.8
Exploit available
Yes
CVE ID(s)
Description
Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Vulnerability
The 'f' parameter of the user/update_profile_pic.php page resource does not validate the contents, extension and type of the file uploaded as a book image, leading to an arbitrary file upload which can be abused to obtain Remote Code Execution. The vulnerable code is located at profile/i.php page:
Our security policy
We have reserved the ID CVE-2023-50760 to refer to this issue from now on.
System Information
Version: Online Notice Board System v1.0
Operating System: Any
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://www.kashipara.com/
Timeline
IA generativa
3 ene 2024
Vendor contacted
3 ene 2024
Public disclosure
3 ene 2024