Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bi1Iha

#29160of 53,630
8.8Total CVSS
Vulnerabilities · 1
PT-2024-34637
8.8
2024-05-20
Sourcecodester · Itsourcecode Vehicle Management System · CVE-2024-5145
**Name of the Vulnerable Software and Affected Versions** SourceCodester Vehicle Management System versions up to 1.0 **Description** A critical issue affects the processing of the file /newdriver.php of the component HTTP POST Request Handler. The manipulation of the `file` argument leads to unrestricted upload. The attack may be initiated remotely. **Recommendations** For SourceCodester Vehicle Management System versions up to 1.0, consider restricting access to the /newdriver.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the `file` argument in the affected HTTP POST Request Handler until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.