CVE-2024-7495: itsourcecode Laravel Accounting System HomeController.php unrestricted upload
A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273621 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7495?
CVE-2024-7495 is classified as a critical vulnerability.
What software is affected by CVE-2024-7495?
CVE-2024-7495 affects itsourcecode Laravel Accounting System version 1.0.
What type of vulnerability is CVE-2024-7495?
CVE-2024-7495 is an unrestricted file upload vulnerability.
How do I fix CVE-2024-7495?
To fix CVE-2024-7495, restrict the file upload functionalities and validate file types before accepting uploads.
What is the impact of CVE-2024-7495?
The impact of CVE-2024-7495 can allow an attacker to upload arbitrary files to the server.