CVE-2024-9815: Codezips Tourist Management System create-package.php unrestricted upload
A vulnerability has been found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/create-package.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9815?
CVE-2024-9815 has been classified as a critical vulnerability.
How does CVE-2024-9815 affect Codezips Tourist Management System 1.0?
CVE-2024-9815 allows for unrestricted file uploads through the manipulation of the packageimage argument in the /admin/create-package.php file.
What are the potential risks associated with CVE-2024-9815?
The exploitation of CVE-2024-9815 could lead to unauthorized access and execution of malicious code on the server.
How can I mitigate CVE-2024-9815?
To mitigate CVE-2024-9815, implement restrictions on file types and sizes that can be uploaded and thoroughly validate user inputs.
Is there a patch available for CVE-2024-9815?
As of now, there is no specific patch mentioned for CVE-2024-9815, but users should follow best security practices to protect their systems.