PT-2024-38360 · Unknown · Itsourcecode Placement Management System

Dee.Mirage

·

Published

2024-08-04

·

Updated

2024-08-09

·

CVE-2024-7450

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions itsourcecode Placement Management System version 1.0
Description A critical issue has been found in the itsourcecode Placement Management System, affecting an unknown functionality of the file /resume upload.php of the component Image Handler. The manipulation of the fileToUpload argument leads to unrestricted upload. The attack can be launched remotely.
Recommendations For itsourcecode Placement Management System version 1.0, consider restricting access to the /resume upload.php file until a patch is available. As a temporary workaround, avoid using the fileToUpload argument in the affected Image Handler component to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-7450

Affected Products

Itsourcecode Placement Management System