PT-2024-16265 · Sourcecodester · Sourcecodester Attendance/Payroll System

K1Nako

·

Published

2024-10-27

·

Updated

2024-10-29

·

CVE-2024-10420

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Attendance and Payroll System version 1.0
Description A critical issue has been found in the upload function of the file /marimar/guest/update.php, allowing unrestricted upload through the manipulation of the image argument. This can be initiated remotely. The exploit has been publicly disclosed and may be used.
Recommendations For SourceCodester Attendance and Payroll System version 1.0, consider disabling the upload function in /marimar/guest/update.php to prevent unrestricted file uploads until a patch is available. Restrict access to the image argument in the update.php file to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-10420

Affected Products

Sourcecodester Attendance/Payroll System