CVE-2024-12233: code-projects Online Notice Board Profile Picture registration.php unrestricted upload
A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12233?
CVE-2024-12233 is classified as a critical vulnerability.
How do I fix CVE-2024-12233?
To mitigate CVE-2024-12233, ensure that file upload mechanisms are properly restricted and implement file type validation in /registration.php.
What components are affected by CVE-2024-12233?
CVE-2024-12233 affects the Profile Picture Handler component in the Online Notice Board version 1.0.
What exploitation does CVE-2024-12233 allow?
CVE-2024-12233 allows for unrestricted file uploads through manipulation of the argument img.
Which version of Online Notice Board is vulnerable to CVE-2024-12233?
Only Online Notice Board version 1.0 is vulnerable to CVE-2024-12233.