An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no upload restrictions for executable files.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://frostylabs.net/writeups/cve-2020-11544/ |     | 
History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T11:35:13.212Z
Reserved: 2020-04-04T00:00:00
Link: CVE-2020-11544
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2020-04-06T16:15:13.457
Modified: 2024-11-21T04:58:07.207
Link: CVE-2020-11544
 Redhat
                        Redhat
                    No data.