First published: Fri Apr 05 2024(Updated: )
Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Complete E-Commerce Site | ||
Donbermoy Complete E-commerce Site | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30849 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
To fix CVE-2024-30849, ensure that proper validation and sanitization are implemented for file uploads in admin/products_photo.php.
CVE-2024-30849 is an arbitrary file upload vulnerability that can lead to remote code execution.
CVE-2024-30849 affects Sourcecodester Complete E-Commerce Site version 1.0.
Yes, CVE-2024-30849 can be exploited remotely by attackers via the filename parameter.