CVE-2024-8089: SourceCodester E-Commerce System controller.php unrestricted upload
A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been classified as critical. Affected is an unknown function of the file /ecommerce/admin/products/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8089?
CVE-2024-8089 has been classified as a critical vulnerability.
How do I fix CVE-2024-8089?
To mitigate CVE-2024-8089, ensure that file upload restrictions are implemented and validate file uploads on the server.
Which version of the software is affected by CVE-2024-8089?
CVE-2024-8089 affects SourceCodester E-Commerce System version 1.0.
What type of vulnerability is CVE-2024-8089?
CVE-2024-8089 is categorized as an unrestricted file upload vulnerability.
Where does CVE-2024-8089 occur in the software?
CVE-2024-8089 occurs in the /ecommerce/admin/products/controller.php file.