PT-2024-37508 · Sourcecodester · Sourcecodester Simple Online Bidding System

Fulou

+1

·

Published

2024-06-24

·

Updated

2024-09-06

·

CVE-2024-6280

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester Simple Online Bidding System version 1.0
Description: A critical issue affects the /admin/ajax.php?action=save settings file, where the manipulation of the img argument leads to unrestricted upload. This can be initiated remotely. The issue has been publicly disclosed and may be exploited.
Recommendations: For SourceCodester Simple Online Bidding System version 1.0, as a temporary workaround, consider restricting access to the /admin/ajax.php?action=save settings file to minimize the risk of exploitation. Avoid using the img argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-6280

Affected Products

Sourcecodester Simple Online Bidding System