First published: Thu Aug 27 2020(Updated: )
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds House Rental And Property Listing Project | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24202 is an arbitrary file upload vulnerability in the File Upload component of Projects World House Rental v1.0.
CVE-2020-24202 has a severity rating of 9.8, which is classified as critical.
CVE-2020-24202 allows remote attackers to upload arbitrary files and potentially execute code on the affected system when exploited by regular users.
At the moment, there is no known fix available for CVE-2020-24202. It is recommended to contact the vendor for updates or consider implementing additional security measures.
You can find more information about CVE-2020-24202 at the following references: [GitHub](https://github.com/hyd3sec/HouseRental_Unauth_RCE/blob/master/HouseRentalRCE.py) and [Projectworlds](https://projectworlds.in/free-projects/php-projects/house-rental-and-property-listing-project-php-mysql/).