Sourcecodester · Sourcecodester Simple File Manager · CVE-2024-2849
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Simple File Manager version 1.0
**Description**
A critical vulnerability was found in the software, affecting unknown code. The manipulation of the `photo` argument leads to unrestricted upload. The attack can be initiated remotely.
**Recommendations**
For version 1.0, consider disabling the file upload feature until a patch is available to prevent unrestricted upload. Restrict access to the `photo` argument to minimize the risk of exploitation.