PT-2024-28784 · Unknown · Sourcecodester Poultry Farm Management System

W3Bn00B3R

·

Published

2024-07-12

·

Updated

2024-08-01

·

CVE-2024-40110

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Poultry Farm Management System version 1.0
Description The issue is related to an Unauthenticated Remote Code Execution (RCE) vulnerability. This vulnerability can be exploited via the productimage parameter at the "/farm/product.php" API endpoint.
Recommendations For Sourcecodester Poultry Farm Management System version 1.0, as a temporary workaround, consider restricting access to the "/farm/product.php" API endpoint to minimize the risk of exploitation. Avoid using the productimage parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-40110

Affected Products

Sourcecodester Poultry Farm Management System