CVE-2024-4349: SourceCodester Pisay Online E-Learning System controller.php unrestricted upload
A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262489 was assigned to this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SourceCodester Pisay Online E-Learning Systemto a version that resolves this vulnerability.Fixed in 1.0Patch VDB-262489
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4349?
CVE-2024-4349 is classified as a critical vulnerability.
How do I fix CVE-2024-4349?
To fix CVE-2024-4349, ensure proper validation and restrictions on file uploads in the /lesson/controller.php file.
What systems are affected by CVE-2024-4349?
CVE-2024-4349 affects the SourceCodester Pisay Online E-Learning System version 1.0.
What type of vulnerability is CVE-2024-4349?
CVE-2024-4349 is an unrestricted file upload vulnerability.
What could an attacker achieve with CVE-2024-4349?
An attacker could exploit CVE-2024-4349 to upload malicious files to the server.