First published: Thu Dec 05 2024(Updated: )
A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fabianros Online Notice Board | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12233 is classified as a critical vulnerability.
To mitigate CVE-2024-12233, ensure that file upload mechanisms are properly restricted and implement file type validation in /registration.php.
CVE-2024-12233 affects the Profile Picture Handler component in the Online Notice Board version 1.0.
CVE-2024-12233 allows for unrestricted file uploads through manipulation of the argument img.
Only Online Notice Board version 1.0 is vulnerable to CVE-2024-12233.