PT-2025-3456 · Unknown · Code-Projects Online Car Rental System

Aaryan Golatkar

·

Published

2025-01-13

·

Updated

2025-01-13

·

CVE-2024-57487

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Code-Projects Online Car Rental System version 1.0
Description The file upload feature in the affected system does not validate file extensions or MIME types, allowing an attacker to upload a PHP shell without restrictions and execute commands on the server.
Recommendations For Code-Projects Online Car Rental System version 1.0, consider disabling the file upload feature until a patch is available to prevent the upload of malicious files, such as PHP shells, and restrict access to sensitive server areas to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-57487

Affected Products

Code-Projects Online Car Rental System