PT-2024-29465 · Unknown · Money Manager Ex Webapp
This Guy
·
Published
2024-10-24
·
Updated
2024-10-29
·
CVE-2024-41617
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Money Manager EX WebApp versions 1.2.2
Description
The issue is related to Incorrect Access Control. The
redirect if not loggedin function in functions security.php fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.Recommendations
For version 1.2.2, as a temporary workaround, consider disabling the
redirect if not loggedin function in functions security.php until a patch is available. Restrict access to file upload functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Money Manager Ex Webapp