Unrestricted File Upload Vulnerability in Airline Reservation System 1.0
CVE-2024-7500

9.8CRITICAL

Key Information:

Vendor
Itsourcecode
Status
Airline Reservation System
Vendor
CVE Published:
6 August 2024

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

Summary

A vulnerability in the itsourcecode Airline Reservation System version 1.0 allows for unrestricted file uploads through the save_settings function in the admin_class.php file. The exploit can be initiated remotely, enabling attackers to manipulate the img argument, potentially leading to unauthorized uploads of malicious files. This vulnerability poses significant risks, as it may be exploited to compromise the integrity and security of the application and its underlying infrastructure. Public disclosure of this issue has raised awareness, and immediate remediation measures are recommended.

Affected Version(s)

Airline Reservation System 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database1 Proof of Concept(s)

Credit

quad (VulDB User)
.