phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.
The vulnerability (CWE-552) consists of insufficient validation and access control of the 'file' parameter in the remove_file.php script. An attacker can pass any file path on the server in this parameter, resulting in its deletion without permission verification. The attack vector is network-based, requires no authentication or user interaction, making exploitation trivial.
An attacker can permanently delete any files accessible to the web server process, including configuration files, application data, system files, or the entire application content, leading to data loss and service unavailability.
Apply patches available from the vendor according to the references. Until an update is applied, it is recommended to remove or secure access to the remove_file.php file (e.g., through web server-level restrictions) and implement access controls and server-side file path validation.
Phpgurukul News Portal Project V4.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HPhpgurukul News Portal
APPPhpgurukul4.1
Related vulnerabilities
Nieautoryzowany upload pliku dowolnego formatu w Phpgurukul News Portal
SQL Injection w Phpgurukul News Portal V4.1 (check_availablity.php)
A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this i...
A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vuln...
A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vuln...