Sankhala-Rohit / Food-Chef-Cafe-Management

Food Chef is a cafe and restaurant management website with both user and admin panel.
34 stars 12 forks source link

unauthenticated RCE vulnerability were found! #1

Open coderMohammed1 opened 2 weeks ago

coderMohammed1 commented 2 weeks ago

Uploading poc2.mp4…

this app security is so poor.

by bypassing authentication via sqli and then exploiting a file upload we can get remote code execution and control the server!

apply filters to fix!

coderMohammed1 commented 2 weeks ago

https://github.com/user-attachments/assets/346e04bc-c087-409a-968c-7aa051a8f172

poc