CVE-2024-1875Unrestricted File Upload in Complaint Management System

Severity
8.8HIGHNVD
CNA6.3
EPSS
0.1%
top 68.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 1

Description

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affects some unknown processing of the file users/register-complaint.php of the component Lodge Complaint Section. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254723.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-q8hf-gfmq-m739: A vulnerability was found in SourceCodester Complaint Management System 12024-02-26
CVEList
SourceCodester Complaint Management System Lodge Complaint Section register-complaint.php unrestricted upload2024-02-25

📋Vendor Advisories

1
Red Hat
kernel: drm/amd/display: Fix potential NULL pointer dereferences in 'dcn10_set_output_transfer_func()'2024-05-01
CVE-2024-1875 — Unrestricted File Upload | cvebase