Unrestricted File Upload Vulnerability in 1000 Projects Portfolio Management System MCA
CVE-2024-12956
Key Information:
- Vendor
- 1000 Projects
- Status
- Portfolio Management System Mca
- Vendor
- CVE Published:
- 26 December 2024
Badges
Summary
A significant vulnerability has been identified in the 1000 Projects Portfolio Management System MCA 1.0, where the functionality found in the file /add_achievement_details.php allows for unrestricted file uploads. The flaw arises from improper handling of the 'ach_certy' argument, which could enable an attacker to upload malicious files without proper validation. This issue has been made public, increasing the risk of exploitation. Organizations utilizing this software must take immediate action to mitigate the risk associated with this vulnerability.
Affected Version(s)
Portfolio Management System MCA 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved