CyberRota Analysis
AI-GeneratedThe SourceCodester Online Book Store System 1.0 has a vulnerability in the administrative interface, specifically within the /admin/index.php file, where improper handling of the 'page' argument allows for remote code execution through manipulated include/require statements. This could lead to unauthorized access or control over the system, making it critical for administrators of affected installations to prioritize patching or mitigating this vulnerability. Organizations using this system should take immediate action to safeguard against potential exploitation, as the exploit is now publicly available.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used.