Unknown · Monbela Tourist Inn Online Reservation System · CVE-2024-6114
Name of the Vulnerable Software and Affected Versions:
Monbela Tourist Inn Online Reservation System versions up to 1.0
Description:
A critical vulnerability has been found in the Monbela Tourist Inn Online Reservation System, affecting an unknown function of the file controller.php. The manipulation of the `image` argument leads to unrestricted upload. This issue can be exploited remotely.
Recommendations:
For Monbela Tourist Inn Online Reservation System versions up to 1.0, as a temporary workaround, consider restricting access to the `controller.php` file or disabling the functionality that allows image uploads until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.