CVE-2024-4920: SourceCodester Online Discussion Forum Site registerH.php unrestricted upload
Published May 16, 2024
·Updated
A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264455.
Affected Software
2 affected components
Sourcecodester Online Discussion Forum Site
Razormist Online Discussion Forum Site=1.0
Event History
May 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Apr 5, 58462
Event
via NVD·11:25 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-4920?
CVE-2024-4920 has been rated as critical.
2
What type of vulnerability is CVE-2024-4920?
CVE-2024-4920 is an unrestricted file upload vulnerability.
3
Which file is affected by CVE-2024-4920?
The vulnerability affects the file registerH.php.
4
Can CVE-2024-4920 be exploited remotely?
Yes, the attack may be initiated remotely.
5
How do I fix CVE-2024-4920?
To fix CVE-2024-4920, implement proper validation and sanitization of file uploads in registerH.php.