CRITICAL
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload
Published Jun 17, 2024
9.8
CRITICALCVSS 3.1
EPSS 1.99%
Description
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
Affected products
No data.
- 1.0
-
Affected
- 1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SourceCodester | Payroll Management System | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-35096 Advisory
- https://github.com/ShellUnease/payroll-management-system-rce ExploitThird Party Advisory
- https://packetstormsecurity.com/files/179106/Payroll-Management-System-1.0-Remote-Code-Execution.html Exploit
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-35096 | Advisory | |
| https://github.com/ShellUnease/payroll-management-system-rce | ExploitThird Party Advisory | |
| https://packetstormsecurity.com/files/179106/Payroll-Management-System-1.0-Remote-Code-Execution.html | Exploit |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 17, 2024
Updated Aug 5, 2024
Reserved May 9, 2024
Link CVE-2024-34833
CISA Vulnrichment
Updated Aug 5, 2024
Red Hat
No data
GitHub
No data