Unrestricted File Upload Vulnerability in Campcodes Legal Case Management System 1.0
CVE-2024-4681
Key Information:
- Vendor
- Campcodes
- Status
- Legal Case Management System
- Vendor
- CVE Published:
- 14 May 2024
Badges
Summary
A security vulnerability in Campcodes Legal Case Management System version 1.0 allows unauthorized users to exploit an argument within the /admin/general-setting file of the Setting Handler component. This flaw facilitates the unrestricted upload of malicious files, presenting a significant risk of remote exploitation. The public disclosure of this vulnerability warrants immediate attention from users to mitigate potential data breaches and unauthorized access.
Affected Version(s)
Legal Case Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved