CVE-2024-2754: SourceCodester Complete E-Commerce Site users_photo.php unrestricted upload
A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/usersphoto.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257544.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2754?
CVE-2024-2754 has been classified as a critical vulnerability.
How does CVE-2024-2754 exploit the system?
CVE-2024-2754 allows attackers to perform unrestricted file uploads through manipulated arguments in the /admin/users_photo.php file.
Which software is affected by CVE-2024-2754?
CVE-2024-2754 affects the SourceCodester Complete E-Commerce Site version 1.0.
What are the potential consequences of CVE-2024-2754?
The exploitation of CVE-2024-2754 can lead to remote attacks that may compromise the server and expose sensitive data.
How can I mitigate the risks associated with CVE-2024-2754?
To mitigate CVE-2024-2754, users should implement strict validations on file uploads to restrict file types and sizes.