CVE-2024-30849: Critical severity sourcecodester complete e-commerce site vulnerability
Published Apr 5, 2024
·Updated
Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/productsphoto.php.
Affected Software
2 affected components
Sourcecodester Complete E-Commerce Site
Donbermoy Complete E-commerce Site=1.0
Event History
Apr 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30849?
CVE-2024-30849 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2024-30849?
To fix CVE-2024-30849, ensure that proper validation and sanitization are implemented for file uploads in admin/products_photo.php.
3
What type of vulnerability is CVE-2024-30849?
CVE-2024-30849 is an arbitrary file upload vulnerability that can lead to remote code execution.
4
Which software is affected by CVE-2024-30849?
CVE-2024-30849 affects Sourcecodester Complete E-Commerce Site version 1.0.
5
Can CVE-2024-30849 be exploited remotely?
Yes, CVE-2024-30849 can be exploited remotely by attackers via the filename parameter.