PT-2024-31976 · Unknown · Best House Rental Management System

Gaorenyusi

·

Published

2024-09-18

·

Updated

2024-09-20

·

CVE-2024-46375

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Best House Rental Management System version 1.0
Description The issue concerns an arbitrary file upload vulnerability in the signup() function of the file rental/admin class.php. This could potentially lead to system compromise. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Best House Rental Management System version 1.0, patch immediately and validate input to prevent exploitation. As a temporary workaround, consider disabling the signup() function until a patch is available. Restrict access to the rental/admin class.php file to minimize the risk of exploitation. Avoid using the vulnerable file upload feature in the signup process until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-46375

Affected Products

Best House Rental Management System