Insufficiently Protected Credentials in Profile Image Handler Could Lead to Remote Exploitation
CVE-2024-7813
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 15 August 2024
Badges
Summary
A vulnerability exists in the SourceCodester Prison Management System 1.0 due to insufficiently protected credentials in the Profile Image Handler component. This issue may allow unauthorized remote attacks that manipulate the file located at /uploadImage/Profile/. The vulnerability exposes sensitive information, potentially enabling attackers to gain access to user credentials without proper safeguards. The public disclosure of this exploit heightens the urgency for affected users to take proactive measures to mitigate risk.
Affected Version(s)
Prison Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved