PT-2024-38360 · Unknown · Itsourcecode Placement Management System
Dee.Mirage
·
Published
2024-08-04
·
Updated
2024-08-09
·
CVE-2024-7450
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
itsourcecode Placement Management System version 1.0
Description
A critical issue has been found in the itsourcecode Placement Management System, affecting an unknown functionality of the file /resume upload.php of the component Image Handler. The manipulation of the
fileToUpload argument leads to unrestricted upload. The attack can be launched remotely.Recommendations
For itsourcecode Placement Management System version 1.0, consider restricting access to the /resume upload.php file until a patch is available. As a temporary workaround, avoid using the
fileToUpload argument in the affected Image Handler component to minimize the risk of exploitation.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Itsourcecode Placement Management System