First published: Tue Jun 18 2024(Updated: )
A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vulnerability is the function uploadImage of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268825 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe Pool Of Bethesda Online Reservation System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6084 is classified as a critical vulnerability.
CVE-2024-6084 affects the Janobe Pool of Bethesda Online Reservation System version 1.0.
The vulnerability occurs in the uploadImage function of the file /admin/mod_room/controller.php when handling the image argument.
CVE-2024-6084 is a file upload vulnerability that can lead to unauthorized file access.
To fix CVE-2024-6084, it is recommended to validate and sanitize file uploads adequately and update the software if a patch is available.