First published: Fri Mar 01 2024(Updated: )
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.
Credit: Shubham Pandey cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Petrol Pump Management Software | ||
Petrol Pump Management Software | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27747 has been classified as a high-severity vulnerability due to its potential to allow arbitrary code execution.
To mitigate CVE-2024-27747, users should validate and sanitize all file uploads and restrict accepted file types in the Petrol Pump Management Software.
CVE-2024-27747 affects version 1.0 of the Petrol Pump Management Software.
There are known exploits for CVE-2024-27747 that use crafted payloads targeting the email Image parameter in the profile.php component.
Attackers can leverage CVE-2024-27747 to execute arbitrary code on the server by uploading malicious files through the vulnerable component.