Unrestricted File Upload Vulnerability in Employee Management System 1.0
CVE-2024-2394
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 12 March 2024
Badges
Summary
An unrestricted upload vulnerability exists in the SourceCodester Employee Management System 1.0, allowing remote attackers to upload arbitrary files through the 'avatar' argument of the /Admin/add-admin.php file. This flaw can lead to significant security risks, including unauthorized access and system compromise. The attack can be initiated remotely, making it a serious concern for users of this software. Immediate action is recommended to mitigate potential threats.
Affected Version(s)
Employee Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved