Unrestricted File Upload Vulnerability in Airline Reservation System 1.0
CVE-2024-7500
Key Information:
- Vendor
- Itsourcecode
- Status
- Airline Reservation System
- Vendor
- CVE Published:
- 6 August 2024
Badges
Summary
A vulnerability in the itsourcecode Airline Reservation System version 1.0 allows for unrestricted file uploads through the save_settings function in the admin_class.php file. The exploit can be initiated remotely, enabling attackers to manipulate the img argument, potentially leading to unauthorized uploads of malicious files. This vulnerability poses significant risks, as it may be exploited to compromise the integrity and security of the application and its underlying infrastructure. Public disclosure of this issue has raised awareness, and immediate remediation measures are recommended.
Affected Version(s)
Airline Reservation System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved