PT-2024-34637 · Sourcecodester · Itsourcecode Vehicle Management System

Bi1Iha

·

Published

2024-05-20

·

Updated

2025-02-10

·

CVE-2024-5145

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Vehicle Management System versions up to 1.0
Description A critical issue affects the processing of the file /newdriver.php of the component HTTP POST Request Handler. The manipulation of the file argument leads to unrestricted upload. The attack may be initiated remotely.
Recommendations For SourceCodester Vehicle Management System versions up to 1.0, consider restricting access to the /newdriver.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the file argument in the affected HTTP POST Request Handler until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-5145

Affected Products

Itsourcecode Vehicle Management System