A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264534 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/CveSecLook/cve/issues/30 | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.264534 | Permissions Required VDB Entry |
https://vuldb.com/?id.264534 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.334216 | Third Party Advisory VDB Entry |
https://github.com/CveSecLook/cve/issues/30 | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.264534 | Permissions Required VDB Entry |
https://vuldb.com/?id.264534 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.334216 | Third Party Advisory VDB Entry |
Configurations
History
10 Feb 2025, 13:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sinamjackson
Sinamjackson schoolwebtech |
|
CPE | cpe:2.3:a:sinamjackson:schoolwebtech:1.0:*:*:*:*:*:*:* | |
References | () https://github.com/CveSecLook/cve/issues/30 - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.264534 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.264534 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.334216 - Third Party Advisory, VDB Entry |
21 Nov 2024, 09:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/CveSecLook/cve/issues/30 - | |
References | () https://vuldb.com/?ctiid.264534 - | |
References | () https://vuldb.com/?id.264534 - | |
References | () https://vuldb.com/?submit.334216 - | |
Summary |
|
16 May 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 7.3 |
16 May 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-16 08:15
Updated : 2025-02-10 13:39
NVD link : CVE-2024-4966
Mitre link : CVE-2024-4966
CVE.ORG link : CVE-2024-4966
JSON object : View
Products Affected
sinamjackson
- schoolwebtech
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type