What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.
Explanation of Vulnerability in Simple Terms
The Salon Booking System allows unauthenticated attackers to upload arbitrary files to the server without restriction. An attacker can upload malicious files—such as PHP scripts—to gain control of the site. No authentication or user interaction is required. This vulnerability affects all versions up to 9.5.
What an attacker can do
Upload and execute arbitrary files on the server, gaining full control of the site.
Potential impact on your site
Complete compromise of the site; attacker can read data, modify content, install backdoors, or take the site offline.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities