CVE-2024-0192: RRJ Nueva Ecija Engineer Online Portal Add Downloadable downloadable.php unrestricted upload

Published Jan 2, 2024
·
Updated

A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file downloadable.php of the component Add Downloadable. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249505 was assigned to this vulnerability.

Affected Software

1 affected component
NIA RRJ Nueva Ecija Engineer Online Portal=1.0

Event History

Jan 2, 2024
CVE Published
08:00 PM
Data Sourced
08:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-0192?

CVE-2024-0192 has been declared as critical.

2

What is the main issue caused by CVE-2024-0192?

The vulnerability in CVE-2024-0192 allows for unrestricted file uploads via downloadable.php.

3

Which component is affected by CVE-2024-0192?

CVE-2024-0192 affects the Add Downloadable component of the RRJ Nueva Ecija Engineer Online Portal.

4

How do I fix CVE-2024-0192?

To fix CVE-2024-0192, ensure that file upload functionality is properly secured and restricted.

5

What software version is affected by CVE-2024-0192?

CVE-2024-0192 affects RRJ Nueva Ecija Engineer Online Portal version 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203