PT-2024-33408 · Sourcecodester · Sourcecodester Simple Online Bidding System
Hefei-Coffee
·
Published
2024-05-16
·
Updated
2024-12-09
·
CVE-2024-4927
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Simple Online Bidding System version 1.0
Description
A critical issue has been found in the system, affecting an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save product. This issue leads to unrestricted upload, allowing remote attacks. The exploit has been disclosed publicly.
Recommendations
For SourceCodester Simple Online Bidding System version 1.0, patch immediately and validate all file uploads to mitigate the risk of malicious file upload. As a temporary workaround, consider restricting access to the /simple-online-bidding-system/admin/ajax.php?action=save product endpoint until a patch is available.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Simple Online Bidding System