Unrestricted File Upload Vulnerability in Itsourcode Online Discussion Forum
CVE-2024-5734
Key Information:
- Vendor
Itsourcecode
- Status
- Vendor
- CVE Published:
- 7 June 2024
Badges
What is CVE-2024-5734?
A significant security vulnerability has been identified in the Itsourcode Online Discussion Forum version 1.0. This flaw resides within an unspecified function of the poster.php file, where improper validation of the argument 'image' permits unauthorized users to upload files without restrictions. This can potentially lead to severe consequences, including remote code execution and full compromise of the affected system. Due to the public disclosure of this exploit, it is crucial for administrators to apply upgrades or patches immediately to safeguard against potential attacks. For more technical details and indicators of compromise, refer to the associated reference materials.
Affected Version(s)
Online Discussion Forum 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved