PT-2024-27796 · Unknown · Itsourcode Online Discussion Forum Project
Limanshu
+2
·
Published
2024-10-04
·
Updated
2024-10-09
·
CVE-2024-37868
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Itsourcecode Online Discussion Forum Project version 1.0
Description
A remote attacker can execute arbitrary code via the "sendreply.php" file due to a File Upload vulnerability. The uploaded file is received using the
$FILES variable. This issue allows for unrestricted file upload, potentially leading to remote code execution. It is recommended to patch immediately and check for signs of exploit. Additionally, auditing all file uploads is advised.Recommendations
For Itsourcecode Online Discussion Forum Project version 1.0, patch the software immediately to fix the File Upload vulnerability. As a temporary workaround, consider restricting access to the "sendreply.php" file until a patch is applied. Also, restrict the use of the
$FILES variable to minimize the risk of exploitation. Audit all file uploads to ensure no malicious files have been uploaded.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Itsourcode Online Discussion Forum Project