A vulnerability was found in itsourcecode Magbanua Beach Resort Online Reservation System up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file controller.php. The manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268856.
References
Link | Resource |
---|---|
https://github.com/Laster-dev/CVE/issues/1 | Exploit |
https://vuldb.com/?ctiid.268856 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.268856 | Third Party Advisory |
https://vuldb.com/?submit.358592 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Aug 2024, 16:12
Type | Values Removed | Values Added |
---|---|---|
First Time |
Janobe
Janobe magbanua Beach Resort Online Reservation System |
|
CPE | cpe:2.3:a:janobe:magbanua_beach_resort_online_reservation_system:1.0:*:*:*:*:*:*:* | |
References | () https://github.com/Laster-dev/CVE/issues/1 - Exploit | |
References | () https://vuldb.com/?ctiid.268856 - Permissions Required, Third Party Advisory | |
References | () https://vuldb.com/?id.268856 - Third Party Advisory | |
References | () https://vuldb.com/?submit.358592 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
20 Jun 2024, 12:44
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 Jun 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-18 12:15
Updated : 2024-08-08 16:12
NVD link : CVE-2024-6110
Mitre link : CVE-2024-6110
CVE.ORG link : CVE-2024-6110
JSON object : View
Products Affected
janobe
- magbanua_beach_resort_online_reservation_system
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type