PT-2024-28826 · Unknown · Simple Library Management System Project Using Php/Mysql
Xiao Huangxin
·
Published
2024-07-16
·
Updated
2024-08-01
·
CVE-2024-40394
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simple Library Management System Project Using PHP/MySQL version 1.0
Description
The issue is related to an arbitrary file upload vulnerability. This vulnerability is present in the
ajax.php component.Recommendations
For version 1.0, consider restricting access to the
ajax.php component to prevent exploitation of the arbitrary file upload vulnerability until a fix is available.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Library Management System Project Using Php/Mysql