Unrestricted File Upload Vulnerability in Campcodes Legal Case Management System 1.0
CVE-2024-4681
4.7MEDIUM
Key Information
- Vendor
- Campcodes
- Status
- Legal Case Management System
- Vendor
- CVE Published:
- 14 May 2024
Summary
A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/general-setting of the component Setting Handler. The manipulation of the argument favicon/logo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263622 is the identifier assigned to this vulnerability.
Affected Version(s)
Legal Case Management System = 1.0
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Risk change from: null to: 4.7 - (MEDIUM)
VulDB entry last update
Vulnerability Reserved.
VulDB entry created
Advisory disclosed
Collectors
NVD DatabaseMitre Database
Credit
yylm (VulDB User)