First published: Mon Jun 17 2024(Updated: )
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Itsourcecode Payroll Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-34833 is considered high due to its potential for remote code execution.
To fix CVE-2024-34833, restrict file upload types to only allow specific file formats and implement server-side validation.
CVE-2024-34833 affects users of Sourcecodester Payroll Management System v1.0 that allows file uploads on the 'save_settings' page.
An attacker exploiting CVE-2024-34833 can upload a malicious PHP file, leading to remote code execution on the server.
Yes, CVE-2024-34833 can be exploited by unauthenticated attackers, making it particularly dangerous.