CVE-2024-10765: Codezips Online Institute Management System profile.php unrestricted upload
A vulnerability classified as critical was found in Codezips Online Institute Management System up to 1.0. This vulnerability affects unknown code of the file /profile.php. The manipulation of the argument oldimage leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10765?
CVE-2024-10765 has been classified as critical due to its potential impact and exploitation risk.
How do I fix CVE-2024-10765?
To fix CVE-2024-10765, you should update the Codezips Online Institute Management System to a version that addresses this vulnerability.
What is the attack vector for CVE-2024-10765?
CVE-2024-10765 can be exploited remotely via the manipulation of the 'old_image' argument in the /profile.php file.
What systems are affected by CVE-2024-10765?
CVE-2024-10765 affects Codezips Online Institute Management System version 1.0.
What type of vulnerability is CVE-2024-10765?
CVE-2024-10765 is an unrestricted file upload vulnerability, allowing attackers to upload unauthorized files.