An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24195
Reference (s):
- https://packetstormsecurity.com/files/158704/Online-Bike-Rental-1.0-Shell-Upload.html
- https://www.sourcecodester.com/php/14374/online-bike-rental-phpmysql.html

