PT-2024-38600 · Sourcecodester · Sourcecodester Prison Management System

Raj Nandi

·

Published

2024-08-15

·

Updated

2024-08-19

·

CVE-2024-7813

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Prison Management System version 1.0
Description A vulnerability has been found in the SourceCodester Prison Management System, affecting some unknown processing of the file /uploadImage/Profile/ of the component Profile Image Handler. The manipulation leads to insufficiently protected credentials. The attack may be initiated remotely.
Recommendations For SourceCodester Prison Management System version 1.0, consider restricting access to the /uploadImage/Profile/ endpoint until a patch is available. As a temporary workaround, review and enhance credential protection mechanisms to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7813

Affected Products

Sourcecodester Prison Management System