PT-2024-18383 · Sourcecodester · Sourcecodester Complaint Management System
Torada
·
Published
2024-02-25
·
Updated
2024-12-10
·
CVE-2024-1875
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Complaint Management System version 1.0
Description
A critical issue affects the Lodge Complaint Section component, specifically the file users/register-complaint.php, leading to unrestricted upload. The attack can be initiated remotely. The issue has been publicly disclosed and may be exploited.
Recommendations
For SourceCodester Complaint Management System version 1.0, consider disabling the
users/register-complaint.php file or restricting access to the Lodge Complaint Section until a patch is available. As a temporary workaround, restrict the upload functionality in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Complaint Management System