A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
References
Link Resource
http://sourcecodester.com Third Party Advisory
https://www.exploit-db.com/exploits/50801 Exploit Third Party Advisory VDB Entry
https://www.sourcecodester.com/sites/default/files/download/oretnom23/apsystem.zip Product Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-03-17T21:17:04

Updated: 2022-03-17T21:17:04

Reserved: 2021-11-22T00:00:00


Link: CVE-2021-44087

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-03-17T22:15:08.810

Modified: 2022-03-24T14:28:43.973


Link: CVE-2021-44087

JSON object: View

cve-icon Redhat Information

No data.