CVE-2024-1818: CodeAstro Membership Management System Logo unrestricted upload
A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /uploads/ of the component Logo Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-254606 is the identifier assigned to this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Apply the vendor-recommended fix for the Logo Handler to remove the ability to perform unrestricted uploads to /uploads; ensure upload permissions/validation are enforced so arbitrary files cannot be uploaded.
CodeAstro Membership Management System (Logo Handler) /uploads unrestricted upload = restricted - Compensating control
Restrict remote access to the web endpoint that serves/handles the /uploads/ directory for the CodeAstro Membership Management System Logo Handler to reduce the risk of unrestricted uploads being exploited remotely.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1818?
CVE-2024-1818 is classified as a critical vulnerability due to the potential for unrestricted file uploads.
How do I fix CVE-2024-1818?
To fix CVE-2024-1818, ensure that file upload restrictions are properly implemented and validate uploaded file types in the CodeAstro Membership Management System.
What systems are affected by CVE-2024-1818?
CVE-2024-1818 affects CodeAstro Membership Management System version 1.0.
What type of vulnerability is CVE-2024-1818?
CVE-2024-1818 is a vulnerability that allows for unrestricted file uploads in the logo handler component.
Can CVE-2024-1818 be exploited remotely?
Yes, CVE-2024-1818 can be exploited remotely, allowing attackers to upload malicious files.