PT-2024-38797 · Unknown · Sourcecodester E-Commerce System

Fany

·

Published

2024-08-22

·

Updated

2024-08-27

·

CVE-2024-8089

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester E-Commerce System version 1.0
Description: A critical issue has been found in the SourceCodester E-Commerce System, affecting an unknown function of the file /ecommerce/admin/products/controller.php. The manipulation of the photo argument leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations: For SourceCodester E-Commerce System version 1.0, as a temporary workaround, consider disabling the upload functionality related to the photo argument until a patch is available. Restrict access to the /ecommerce/admin/products/controller.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-8089

Affected Products

Sourcecodester E-Commerce System