First published: Tue Jan 02 2024(Updated: )
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file downloadable.php of the component Add Downloadable. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249505 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Engineers Online Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0192 has been declared as critical.
The vulnerability in CVE-2024-0192 allows for unrestricted file uploads via downloadable.php.
CVE-2024-0192 affects the Add Downloadable component of the RRJ Nueva Ecija Engineer Online Portal.
To fix CVE-2024-0192, ensure that file upload functionality is properly secured and restricted.
CVE-2024-0192 affects RRJ Nueva Ecija Engineer Online Portal version 1.0.