Impact
A vulnerability exists in itsourcecode Payroll System 1.0 within the save_settings function of admin_class.php. The function accepts an img parameter that can be manipulated to upload arbitrary files, and the upload capability is unrestricted, allowing an attacker to upload a malicious script or other executable content that may be executed on the server, compromising confidentiality, integrity, or availability of the system. The flaw is classified as broken access control (CWE‑284) and an unrestricted upload of dangerous files (CWE‑434).
Affected Systems
The affected vendor is itsourcecode and the product is Payroll System version 1.0. No additional versions or configurations are specified.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The description states that the attack may be performed from remote, implying that remote access to the administrative interface is required. The exploitation path would involve authenticating as an administrator or using stolen credentials, then submitting a crafted image upload request to trigger the vulnerability. Once a malicious file is stored and executed, the attacker could gain unauthorized system access.
OpenCVE Enrichment