CVE-2024-6280: SourceCodester Simple Online Bidding System unrestricted upload
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/ajax.php?action=savesettings. The manipulation of the argument img leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269493 was assigned to this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update/patch the Simple Online Bidding System to prevent unrestricted upload via manipulation of the img argument that leads to uploading through /admin/ajax.php?action=save_settings (VDB-269493).
SourceCodester Simple Online Bidding System unrestricted upload handling = blocked - Compensating control
Restrict network access to the Simple Online Bidding System endpoint /admin/ajax.php?action=save_settings (e.g., via firewall/ACL/WAF) to mitigate remote exploitation of the unrestricted upload vulnerability (VDB-269493).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6280?
CVE-2024-6280 has been classified as critical.
How do I fix CVE-2024-6280?
To fix CVE-2024-6280, restrict the file upload settings in the /admin/ajax.php?action=save_settings file.
What systems are affected by CVE-2024-6280?
CVE-2024-6280 affects SourceCodester Simple Online Bidding System version 1.0.
What type of attack does CVE-2024-6280 allow?
CVE-2024-6280 allows for unrestricted file uploads due to improper handling of the img argument.
Can CVE-2024-6280 lead to further vulnerabilities?
Yes, CVE-2024-6280 can open up the system to potential malicious uploads, leading to further security risks.