CVE-2024-12954: 1000 Projects Portfolio Management System MCA update_ach.php unrestricted upload
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. This affects an unknown part of the file /updateach.php. The manipulation of the argument achcerty leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12954?
CVE-2024-12954 is classified as a critical vulnerability.
How do I fix CVE-2024-12954?
To fix CVE-2024-12954, secure the upload functionality in the /update_ach.php file to prevent unrestricted uploads.
What is affected by CVE-2024-12954?
CVE-2024-12954 affects the 1000 Projects Portfolio Management System MCA version 1.0.
What type of vulnerability is CVE-2024-12954?
CVE-2024-12954 is an unrestricted file upload vulnerability.
What could happen if CVE-2024-12954 is exploited?
Exploitation of CVE-2024-12954 could allow an attacker to upload malicious files, potentially compromising the system.