CVE-2024-11661

A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file profile.php of the component Profile Image Handler. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The researcher submit confuses the vulnerability class of this issue.
References
Link Resource
https://github.com/anqi12301/CVE/issues/1 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.285982 Permissions Required
https://vuldb.com/?id.285982 Third Party Advisory
https://vuldb.com/?submit.447115 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:codezips:free_exam_hall_seating_management_system:1.0:*:*:*:*:*:*:*

History

04 Dec 2024, 18:41

Type Values Removed Values Added
First Time Codezips free Exam Hall Seating Management System
Codezips
CPE cpe:2.3:a:codezips:free_exam_hall_seating_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/anqi12301/CVE/issues/1 - () https://github.com/anqi12301/CVE/issues/1 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.285982 - () https://vuldb.com/?ctiid.285982 - Permissions Required
References () https://vuldb.com/?id.285982 - () https://vuldb.com/?id.285982 - Third Party Advisory
References () https://vuldb.com/?submit.447115 - () https://vuldb.com/?submit.447115 - Third Party Advisory
Summary
  • (es) Se ha encontrado una vulnerabilidad en Codezips Free Exam Hall Seating Management System 1.0. Se ha declarado como problemática. Esta vulnerabilidad afecta al código desconocido del archivo profile.php del componente Profile Image Handler. La manipulación del argumento image conduce a una carga sin restricciones. El ataque se puede iniciar de forma remota. El investigador envía información confusa sobre la clase de vulnerabilidad de este problema.

25 Nov 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-25 08:15

Updated : 2024-12-04 18:41


NVD link : CVE-2024-11661

Mitre link : CVE-2024-11661

CVE.ORG link : CVE-2024-11661


JSON object : View

Products Affected

codezips

  • free_exam_hall_seating_management_system
CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type