First published: Tue Jun 18 2024(Updated: )
A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268856.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe Magbanua Beach Resort Online Reservation System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6110 is rated as critical.
CVE-2024-6110 allows for unrestricted file uploads due to a vulnerability in the file controller.php.
CVE-2024-6110 affects version 1.0 of the Magbanua Beach Resort Online Reservation System.
CVE-2024-6110 can lead to unauthorized access and exploitation of the system through malicious file uploads.
To fix CVE-2024-6110, implement file upload validation and restrict file types and sizes in the affected system.