CVE-2024-32256: Malicious File Upload
Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there are no checks for what types of files are uploaded from the image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32256?
CVE-2024-32256 has a high severity level due to its potential for allowing attackers to upload malicious files.
How do I fix CVE-2024-32256?
To fix CVE-2024-32256, implement file type validation and restrict uploads to only permitted file types on the /tms/admin/change-image.php endpoint.
What are the risks associated with CVE-2024-32256?
The risks of CVE-2024-32256 include unauthorized access, system compromise, and the potential for executing arbitrary code on the server.
Which versions of Phpgurukul Tourism Management System are affected by CVE-2024-32256?
CVE-2024-32256 affects Phpgurukul Tourism Management System version 2.0.
What action should users of Phpgurukul Tourism Management System take regarding CVE-2024-32256?
Users of Phpgurukul Tourism Management System should urgently apply the recommended security patch and update their software to mitigate the vulnerability.