
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE
Sourcecodester Covid-19 Contact Tracing System 1.0 – Unrestricted File Upload Leading to Remote Code Execution
Sourcecodester Covid-19 Contact Tracing System version 1.0 contains a vulnerability classified as Unrestricted Upload of File with Dangerous Type (CWE-434). The application fails to properly validate uploaded file types in a file upload functionality, allowing remote attackers to upload arbitrary files that may be executed by the server. Successful exploitation of this vulnerability may result in remote code execution with the privileges of the web server process. The vulnerability can be exploited remotely and may impact confidentiality, integrity, and availability of the affected system.
An attacker exploiting this vulnerability may be able to execute arbitrary code on the target server. Depending on the server configuration, this could lead to full system compromise, unauthorized access to sensitive data, modification of application behavior, or service disruption.
Exploitation requires access to the affected file upload functionality and the ability to upload files without adequate server-side validation of file type, extension, or content. No public exploit code is provided as part of this disclosure.
It is recommended that affected users: