Unrestricted File Upload Vulnerability in ItsSourceCode Online Bookstore 1.0
CVE-2024-9036
Key Information:
- Vendor
Itsourcecode
- Status
- Vendor
- CVE Published:
- 20 September 2024
Badges
What is CVE-2024-9036?
A security vulnerability exists within the itsourcecode Online Bookstore version 1.0, specifically in the admin_add.php file. This weakness allows for unrestricted file uploads when specific parameters are manipulated, particularly the image argument. Due to this flaw, attackers are capable of initiating exploits remotely, which could lead to unauthorized files being uploaded to the server. The exploit has been publicly disclosed, raising concerns over potential attacks on affected installations. Web administrators are urged to evaluate their systems and apply necessary mitigations.
Affected Version(s)
Online Bookstore 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.