PT-2024-38385 · Unknown · Laravel Accounting System

Dee.Mirage

·

Published

2024-08-06

·

Updated

2024-08-19

·

CVE-2024-7495

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Laravel Accounting System version 1.0
Description A critical issue was found in the Laravel Accounting System, affecting an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the image argument leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Laravel Accounting System version 1.0, as a temporary workaround, consider restricting access to the app/Http/Controllers/HomeController.php file or disabling the functionality that allows image uploads until a patch is available. Restrict the use of the image argument in the affected controller to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-7495

Affected Products

Laravel Accounting System