Aller au contenu

Fiche vulnérabilité

CVE-2024-7189 : faille critique kevinwong online food ordering system (CVSS 9.8)

Description

A vulnerability classified as critical has been found in itsourcecode Online Food Ordering System 1.0. Affected is an unknown function of the file editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272610 is the identifier assigned to this vulnerability.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
29 juil. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • kevinwong online food ordering system

Références

Rechercher une autre vulnérabilité dans la base CVE