PT-2024-33408 · Sourcecodester · Sourcecodester Simple Online Bidding System

·

CVE-2024-4927

·

Published

2024-05-16

·

Updated

2024-12-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Simple Online Bidding System version 1.0
Description A critical issue has been found in the system, affecting an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save product. This issue leads to unrestricted upload, allowing remote attacks. The exploit has been disclosed publicly.
Recommendations For SourceCodester Simple Online Bidding System version 1.0, patch immediately and validate all file uploads to mitigate the risk of malicious file upload. As a temporary workaround, consider restricting access to the /simple-online-bidding-system/admin/ajax.php?action=save product endpoint until a patch is available.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4927

Affected Products

Sourcecodester Simple Online Bidding System