PT-2024-33408 · Sourcecodester · Sourcecodester Simple Online Bidding System

Hefei-Coffee

·

Published

2024-05-16

·

Updated

2024-12-09

·

CVE-2024-4927

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Simple Online Bidding System version 1.0
Description A critical issue has been found in the system, affecting an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save product. This issue leads to unrestricted upload, allowing remote attacks. The exploit has been disclosed publicly.
Recommendations For SourceCodester Simple Online Bidding System version 1.0, patch immediately and validate all file uploads to mitigate the risk of malicious file upload. As a temporary workaround, consider restricting access to the /simple-online-bidding-system/admin/ajax.php?action=save product endpoint until a patch is available.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-4927

Affected Products

Sourcecodester Simple Online Bidding System