PT-2024-29465 · Unknown · Money Manager Ex Webapp

This Guy

·

Published

2024-10-24

·

Updated

2024-10-29

·

CVE-2024-41617

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Money Manager EX WebApp versions 1.2.2
Description The issue is related to Incorrect Access Control. The redirect if not loggedin function in functions security.php fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.
Recommendations For version 1.2.2, as a temporary workaround, consider disabling the redirect if not loggedin function in functions security.php until a patch is available. Restrict access to file upload functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-41617

Affected Products

Money Manager Ex Webapp