PT-2024-16254 · Unknown · Sourcecodester Online Hotel Reservation System

K1Nako

·

Published

2024-10-27

·

Updated

2024-10-29

·

CVE-2024-10410

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Online Hotel Reservation System version 1.0
Description A critical issue was found in the function upload of the file /admin/mod room/controller.php?action=add. The manipulation of the image argument leads to unrestricted upload. The attack can be launched remotely.
Recommendations For SourceCodester Online Hotel Reservation System version 1.0, consider disabling the upload function in the /admin/mod room/controller.php?action=add file until a patch is available. Restrict access to the image argument to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-10410

Affected Products

Sourcecodester Online Hotel Reservation System