CVE-2024-12951: 1000 Projects Portfolio Management System MCA add_personal_details.php unrestricted upload
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /addpersonaldetails.php. The manipulation of the argument profile leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12951?
CVE-2024-12951 is classified as a critical vulnerability.
What systems are affected by CVE-2024-12951?
CVE-2024-12951 affects the 1000 Projects Portfolio Management System MCA version 1.0.
How does CVE-2024-12951 exploit the vulnerability?
CVE-2024-12951 allows for unrestricted file uploads through the manipulation of the profile argument in the /add_personal_details.php file.
How do I fix CVE-2024-12951?
To mitigate CVE-2024-12951, it is recommended to restrict file upload functionalities and validate user inputs on the affected file.
What impact does CVE-2024-12951 have on systems?
CVE-2024-12951 can lead to unauthorized file uploads, potentially compromising the integrity of the system.