Unrestricted File Upload Vulnerability in SourceCodester Online Discussion Forum Site 1.0
CVE-2024-2690
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 20 March 2024
Badges
Summary
A vulnerability has been identified in the SourceCodester Online Discussion Forum Site version 1.0, specifically within the /uupdate.php file. This flaw allows remote attackers to exploit the application by manipulating the 'ima' argument, leading to unrestricted file uploads. The potential for this vulnerability can result in the execution of malicious scripts on the server, which may compromise the entire application and its users. The exploit has been publicly disclosed, making it crucial for administrators to review their systems and implement security measures to mitigate any associated risks.
Affected Version(s)
Online Discussion Forum Site 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved