CVE-2024-10993: Codezips Online Institute Management System manage_website.php unrestricted upload
A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of the file /managewebsite.php. The manipulation of the argument websiteimage leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10993?
CVE-2024-10993 is classified as a critical vulnerability due to unrestricted file upload capabilities.
How do I fix CVE-2024-10993?
Fix CVE-2024-10993 by implementing proper file upload validation and restricting the types of files that can be uploaded.
What is affected by CVE-2024-10993?
CVE-2024-10993 affects Codezips Online Institute Management System version 1.0.
What kind of attack can CVE-2024-10993 enable?
CVE-2024-10993 can enable attackers to upload malicious files to the server.
Where does the vulnerability CVE-2024-10993 occur?
The vulnerability CVE-2024-10993 occurs in the /manage_website.php file within the application.