PT-2024-16528 · Unknown · Codezips Free Exam Hall Seating Management System

Tiki

·

Published

2024-11-04

·

Updated

2024-11-06

·

CVE-2024-10766

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Codezips Free Exam Hall Seating Management System version 1.0
Description A critical issue has been found in the system, affecting the processing of the file /pages/save user.php. The manipulation of the image argument leads to unrestricted upload. The attack may be initiated remotely.
Recommendations For Codezips Free Exam Hall Seating Management System version 1.0, consider disabling the upload functionality in the /pages/save user.php file until a patch is available. Restrict access to the image argument to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Incorrect Privilege Assignment

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-10766

Affected Products

Codezips Free Exam Hall Seating Management System