"value":"Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin panel has an upload function of profile photo accessible at http://localhost/scheduler/admin/?page=user. An attacker could upload a malicious file such as shell.php with the Content-Type: image/png. Then, the attacker have to visit the uploaded profile photo to access the shell."
},
{
"lang":"es",
"value":"Sourcecodester Online Covid Vaccination Scheduler System versi\u00f3n 1.0, est\u00e1 afectado y es vulnerable a una Carga de Archivos Arbitraria. El panel de administraci\u00f3n presenta una funci\u00f3n de carga de la foto del perfil accesible en http://localhost/scheduler/admin/?page=user. Un atacante podr\u00eda subir un archivo malicioso como shell.php con el Content-Type: image/png. Entonces, el atacante tiene que visitar la foto de perfil cargada para acceder al shell"