1 results (0.003 seconds)
CVSS: 5.8EPSS: 0%CPEs: 1EXPL: 1
CVE-2024-2754 – SourceCodester Complete E-Commerce Site users_photo.php unrestricted upload
https://notcve.org/view.php?id=CVE-2024-2754
A vulnerability classified as critical has been found in SourceCodester Complete E-Commerce Site 1.0. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/wkeyi0x1/vul-report/issues/4 https://vuldb.com/?ctiid.257544 https://vuldb.com/?id.257544 • CWE-434: Unrestricted Upload of File with Dangerous Type •