First published: Sun Apr 07 2024(Updated: )
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Admin/edit-photo.php of the component Avatar Handler. The manipulation of the argument avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259630 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prison Management System | =1.0 | |
Prison Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3436 has been classified as a critical vulnerability.
CVE-2024-3436 affects the Avatar Handler located in /Admin/edit-photo.php of the SourceCodester Prison Management System.
CVE-2024-3436 allows for unrestricted file uploads through manipulation of the avatar argument.
Fixing CVE-2024-3436 involves implementing strict validation on file uploads and ensuring proper file type restrictions.
As of now, there is no official patch released for CVE-2024-3436, and users are advised to monitor updates from the vendor.