CVE-2024-0465: code-projects Employee Profile Management System download.php path traversal
A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument downloadfile leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-250570 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0465?
CVE-2024-0465 is classified as problematic due to path traversal vulnerabilities.
How do I fix CVE-2024-0465?
To fix CVE-2024-0465, sanitize input on the download_file argument to prevent path traversal attacks.
What types of attacks can CVE-2024-0465 lead to?
CVE-2024-0465 can lead to unauthorized file access through path traversal exploitation.
Which software is affected by CVE-2024-0465?
CVE-2024-0465 affects version 1.0 of code-projects Employee Profile Management System.
What file is primarily affected by CVE-2024-0465?
The vulnerability impacts the download.php file in the Employee Profile Management System.