First published: Thu Mar 21 2024(Updated: )
A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257544.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Complete E-Commerce Site | ||
Donbermoy Complete E-commerce Site | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2754 has been classified as a critical vulnerability.
CVE-2024-2754 allows attackers to perform unrestricted file uploads through manipulated arguments in the /admin/users_photo.php file.
CVE-2024-2754 affects the SourceCodester Complete E-Commerce Site version 1.0.
The exploitation of CVE-2024-2754 can lead to remote attacks that may compromise the server and expose sensitive data.
To mitigate CVE-2024-2754, users should implement strict validations on file uploads to restrict file types and sizes.