Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-1391

March 14, 2023, 3:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222978 is the identifier assigned to this vulnerability.

cve

Senior Cloud Security Operations Engineer - AWS

@ MUFG Investor Services | London, United Kingdom

Cybersecurity Engineer (ForgeRock openAM, SAML, OpenID, OAuth)

@ Visa | Bengaluru, India

Software Engineer, Product Security

@ Block | San Francisco, CA, United States

Security Internship - Application Security Intern

@ Highspot | Vancouver, BC

Cloud Security Engineer

@ XOR Security | Washington, DC

Cyber Security Consultant Intern - ETAS

@ Bosch Group | Plymouth, MI, United States

Senior Vulnerability & Security Configuration Engineer

@ ServiceNow | Atlanta, GA, United States

Insider Risk Monitoring & Triage Security Engineer

@ Block | San Francisco, CA, United States

Senior Cybersecurity Engineer | Sydney

@ Datacom | Sydney, New South Wales, Australia

Zero Trust Architect

@ XOR Security | Washington, DC

Sr. Technical Consultant - Sydney

@ Elastic | Sydney, Australia

Lead, Compliance

@ Gemini | New York City; Seattle, Washington; San Francisco, California