Unrestricted File Upload Vulnerability in Codezips Online Institute Management System
CVE-2024-10993
Key Information:
- Vendor
- Codezips
- Status
- Online Institute Management System
- Vendor
- CVE Published:
- 8 November 2024
Badges
Summary
A severe security vulnerability has been identified within the Codezips Online Institute Management System 1.0 that allows attackers to exploit a flaw in the /manage_website.php file. This vulnerability centers around the manipulation of the 'website_image' argument, enabling unrestricted file uploads. As a result, an attacker can remotely gain access to the server and upload malicious files, potentially leading to further exploitation and unauthorized access to sensitive data. Given its public disclosure, immediate mitigation strategies are advised to protect against possible attacks.
Affected Version(s)
Online Institute Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved