MEDIUM
SourceCodester Drag and Drop Image Upload upload.php unrestricted upload
Published Oct 15, 2024
5.3
MEDIUMCVSS 4.0
EPSS 0.58%
Description
A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SourceCodester | Drag and Drop Image Upload | n/a |
|
- 1.0
-
- Version 1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SourceCodester | Drag and Drop Image Upload | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-50256 Advisory
- https://github.com/JunMing27/CVE/blob/main/SourceCodester%20-%20Arbitrary%20File%20Upload%20vulnerability%20leads%20to%20RCE%20in%20Drag%20and%20Drop%20Image%20Upload%20without%20Refresh%20Reload%20Using%20PHP%20and%20Ajax.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.280340 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.280340 vdb-entryPermissions Required
- https://vuldb.com/?submit.423445 third-party-advisoryThird Party Advisory
- https://www.sourcecodester.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-50256 | Advisory | |
| https://github.com/JunMing27/CVE/blob/main/SourceCodester%20-%20Arbitrary%20File%20Upload%20vulnerability%20leads%20to%20RCE%20in%20Drag%20and%20Drop%20Image%20Upload%20without%20Refresh%20Reload%20Using%20PHP%20and%20Ajax.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.280340 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.280340 | vdb-entryPermissions Required | |
| https://vuldb.com/?submit.423445 | third-party-advisoryThird Party Advisory | |
| https://www.sourcecodester.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Oct 15, 2024
Updated Oct 15, 2024
Reserved Oct 15, 2024
Link CVE-2024-9975
CISA Vulnrichment
Updated Oct 15, 2024
ENISA EUVD
EUVD-2024-50256 Assigner VulDB
Published Oct 15, 2024
Updated Oct 15, 2024
Exploited since n/a
Link EUVD-2024-50256