CVE-2024-3436: SourceCodester Prison Management System Avatar edit-photo.php unrestricted upload
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Admin/edit-photo.php of the component Avatar Handler. The manipulation of the argument avatar leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259630 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3436?
CVE-2024-3436 has been classified as a critical vulnerability.
What components are affected by CVE-2024-3436?
CVE-2024-3436 affects the Avatar Handler located in /Admin/edit-photo.php of the SourceCodester Prison Management System.
How does CVE-2024-3436 affect the software?
CVE-2024-3436 allows for unrestricted file uploads through manipulation of the avatar argument.
How do I fix CVE-2024-3436?
Fixing CVE-2024-3436 involves implementing strict validation on file uploads and ensuring proper file type restrictions.
Is there a patch available for CVE-2024-3436?
As of now, there is no official patch released for CVE-2024-3436, and users are advised to monitor updates from the vendor.