CVE-2020-11544
Last modified
CVE-2020-11544 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for executable files.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Official Car Rental System | 1.0 |
References
- https://frostylabs.net/writeups/cve-2020-11544/Exploit, Third Party Advisory
- https://frostylabs.net/writeups/cve-2020-11544/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-11544?
How severe is CVE-2020-11544?
How do I fix CVE-2020-11544?
Are you affected by CVE-2020-11544?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
