Insufficiently Protected Credentials in Profile Image Handler Could Lead to Remote Exploitation
CVE-2024-7813

7.5HIGH

Key Information:

Vendor
CVE Published:
15 August 2024

Badges

👾 Exploit Exists🟡 Public PoC

Summary

A vulnerability exists in the SourceCodester Prison Management System 1.0 due to insufficiently protected credentials in the Profile Image Handler component. This issue may allow unauthorized remote attacks that manipulate the file located at /uploadImage/Profile/. The vulnerability exposes sensitive information, potentially enabling attackers to gain access to user credentials without proper safeguards. The public disclosure of this exploit heightens the urgency for affected users to take proactive measures to mitigate risk.

Affected Version(s)

Prison Management System 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Raj Nandi (VulDB User)
.