Critical Vulnerability in ItsSourceCode Online Discussion Forum 1.0 Allows Unrestricted File Upload
CVE-2024-5518
6.3MEDIUM
Key Information
- Vendor
- Itsourcecode
- Status
- Online Discussion Forum
- Vendor
- CVE Published:
- 30 May 2024
Summary
A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_profile_picture.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266589 was assigned to this vulnerability.
Affected Version(s)
Online Discussion Forum = 1.0
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Risk change from: null to: 6.3 - (MEDIUM)
VulDB entry last update
Vulnerability Reserved.
VulDB entry created
Advisory disclosed
Vulnerability published.
Collectors
NVD DatabaseMitre Database
Credit
N3xu5Cr4ck37 (VulDB User)