Impact
SourceCodester Online Faculty Clearance System 1.0 is vulnerable to an unrestricted file upload through the move_uploaded_file function in edit_picture.php. An attacker can manipulate the File argument to upload any file type, which may include executable scripts. This vulnerability allows the attacker to place malicious files on the web server, potentially leading to remote code execution or denial of service depending on the server configuration. The weakness corresponds to improper access control and unfiltered file typing.
Affected Systems
The affected system is the SourceCodester Online Faculty Clearance System, version 1.0, used for faculty clearance processes. The vulnerability resides in the Profile Picture Upload feature within edit_picture.php.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild at this time. The vulnerability is not listed in the CISA KEV catalog, and no known active exploitation campaigns have been reported. However, the attack vector is remote, and the exploit has been publicly disclosed, meaning the system exposed to the internet. Risk to affected organizations arises from the potential to upload arbitrary files that could be executed by the web server, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment