Aller au contenu

Fiche vulnérabilité

CVE-2024-7910 : faille élevée online railway reservation system… (CVSS 7.2)

Description

A vulnerability was found in CodeAstro Online Railway Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/emp-profile-avatar.php of the component Profile Photo Update Handler. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
18 août 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • online railway reservation system project online railway reservation system

Références

Rechercher une autre vulnérabilité dans la base CVE