PT-2024-17828 · Unknown · 1000 Projects Portfolio Management System Mca

Wangjiawei

·

Published

2024-12-26

·

Updated

2024-12-26

·

CVE-2024-12956

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 1000 Projects Portfolio Management System MCA version 1.0
Description A critical issue affects the processing of the file /add achievement details.php, where the manipulation of the argument ach certy leads to unrestricted upload. The attack can be initiated remotely.
Recommendations For version 1.0, consider restricting access to the /add achievement details.php file until a patch is available. As a temporary workaround, avoid using the ach certy argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-12956

Affected Products

1000 Projects Portfolio Management System Mca