CVE-2023-43740
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Sep 28, 2023
Updated: Oct 6, 2023
CWE ID 434
Summary
CVE-2023-43740 is a critical vulnerability affecting the Online Book Store Project v1.0. An attacker with administrative access can exploit the insecure file upload functionality on the admin_edit.php page by uploading a malicious file to the 'image' parameter. This vulnerability grants the attacker remote code execution capabilities on the server hosting the application, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share