Back

CRITICAL

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload

Published Jun 17, 2024

Description

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Jun 17, 2024
Updated Aug 5, 2024
Reserved May 9, 2024

CISA Vulnrichment

Updated Aug 5, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Jun 17, 2024
Updated Aug 5, 2024

GitHub

No data