CVE-2024-0192: RRJ Nueva Ecija Engineer Online Portal Add Downloadable downloadable.php unrestricted upload
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file downloadable.php of the component Add Downloadable. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249505 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0192?
CVE-2024-0192 has been declared as critical.
What is the main issue caused by CVE-2024-0192?
The vulnerability in CVE-2024-0192 allows for unrestricted file uploads via downloadable.php.
Which component is affected by CVE-2024-0192?
CVE-2024-0192 affects the Add Downloadable component of the RRJ Nueva Ecija Engineer Online Portal.
How do I fix CVE-2024-0192?
To fix CVE-2024-0192, ensure that file upload functionality is properly secured and restricted.
What software version is affected by CVE-2024-0192?
CVE-2024-0192 affects RRJ Nueva Ecija Engineer Online Portal version 1.0.