CVE-2024-0465
code-projects Employee Profile Management System download.php path traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-250570 is the identifier assigned to this vulnerability.
Una vulnerabilidad fue encontrada en code-projects Employee Profile Management System 1.0 y clasificada como problemática. Esta vulnerabilidad afecta a un código desconocido del archivo download.php. La manipulación del argumento download_file conduce a path traversal: '../filedir'. La explotación ha sido divulgada al público y puede utilizarse. VDB-250570 es el identificador asignado a esta vulnerabilidad.
In code-projects Employee Profile Management System 1.0 wurde eine Schwachstelle entdeckt. Sie wurde als problematisch eingestuft. Es geht um eine nicht näher bekannte Funktion der Datei download.php. Dank Manipulation des Arguments download_file mit unbekannten Daten kann eine path traversal: '../filedir'-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-12 CVE Reserved
- 2024-01-12 CVE Published
- 2024-01-21 EPSS Updated
- 2024-08-01 CVE Updated
- 2024-08-01 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-24: Path Traversal: '../filedir'
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.250570 | Technical Description |
URL | Date | SRC |
---|---|---|
https://github.com/BxYQ/vul/blob/main/EMPLOYEE_PROFILE_MANAGEMENT_SYSTEM%20_FileRead.pdf | 2024-08-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Code-projects Search vendor "Code-projects" | Employee Profile Management System Search vendor "Code-projects" for product "Employee Profile Management System" | 1.0 Search vendor "Code-projects" for product "Employee Profile Management System" and version "1.0" | - |
Affected
|