First published: Wed Sep 09 2020(Updated: )
An Arbitrary File Upload in the Upload Image component in Sourcecodester Online Bike Rental v1.0 allows authenticated administrator to conduct remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Online Bike Rental | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24195 is categorized as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2020-24195, ensure that file upload validations are implemented and restrict file types that can be uploaded.
CVE-2020-24195 affects authenticated administrators of Online Bike Rental version 1.0.
CVE-2020-24195 is an arbitrary file upload vulnerability that allows for remote code execution.
No, CVE-2020-24195 requires authentication as an administrator to exploit.