CVE-2024-6084: itsourcecode Pool of Bethesda Online Reservation System uploadImage unrestricted upload
A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vulnerability is the function uploadImage of the file /admin/modroom/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268825 was assigned to this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
itsourcecode Pool of Bethesda Online Reservation Systemto a version that resolves this vulnerability.Fixed in 1.0Patch VDB-268825
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6084?
CVE-2024-6084 is classified as a critical vulnerability.
Which software versions are affected by CVE-2024-6084?
CVE-2024-6084 affects the Janobe Pool of Bethesda Online Reservation System version 1.0.
How does the CVE-2024-6084 vulnerability occur?
The vulnerability occurs in the uploadImage function of the file /admin/mod_room/controller.php when handling the image argument.
What type of vulnerability is CVE-2024-6084?
CVE-2024-6084 is a file upload vulnerability that can lead to unauthorized file access.
How can I fix CVE-2024-6084?
To fix CVE-2024-6084, it is recommended to validate and sanitize file uploads adequately and update the software if a patch is available.