PT-2024-33158 · Unknown · Prison Management System

Aobo Li

·

Published

2024-10-28

·

Updated

2024-10-30

·

CVE-2024-48594

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Prison Management System version 1.0
Description The issue allows a remote attacker to execute arbitrary code via the file upload component. This is a result of a File Upload vulnerability in the Prison Management System.
Recommendations For Prison Management System version 1.0, consider disabling the file upload component until a patch is available to prevent exploitation. Restrict access to the file upload functionality to minimize the risk of arbitrary code execution.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-48594

Affected Products

Prison Management System