Codezips Tourist Management System 1.0 /admin/change-image.php packageimage ବିସ୍ତାରିତ ଅଧିକାର
Dogoggorri kan akka ଜଟିଳ jedhamuun ramadame Codezips Tourist Management System 1.0 keessatti argameera. Miidhamni argame is hojii hin beekamne faayilii /admin/change-image.php keessa. Wanti jijjiirame irratti packageimage gara ବିସ୍ତାରିତ ଅଧିକାର geessa. Rakkoo ibsuuf CWE yoo fayyadamte gara CWE-434 si geessa. Odeeffannoon kun yeroo 10/10/2024 maxxanfameera. Odeeffannoon kun buufachuuf github.com irratti argama. Dogoggorri kun CVE-2024-9816 jedhamee waamama. Weerara fageenya irraa jalqabuu ni danda'ama. Ibsa teeknikaa ni jira. Waan dabalataa ta’een, meeshaa balaa kana fayyadamuuf ni jira. Qorannoo miidhaa (exploit) uummataaf ifa taasifameera, kanaafis fayyadamuu ni danda'ama. Ammas, gatii exploit might be approx. USD $0-$5k yeroo ammaa irratti argamuu danda'a. ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ ta’uu isaa ibsameera. Exploit github.com irraa buufachuun ni danda'ama. Akka 0-daytti, gatiin isaa daldala dhoksaa keessatti $0-$5k akka ta'e tilmaamameera. If you want to get best quality of vulnerability data, you may have to visit VulDB.
2 ଆଡାପ୍ଟେସନ୍ · 85 ପଏଣ୍ଟ
| ଫିଲ୍ଡ | ସୃଷ୍ଟି ହୋଇଛି 10/10/2024 10:50 AM | ଅଦ୍ୟତନ 1/1 10/11/2024 11:32 AM |
|---|---|---|
| software_vendor | Codezips | Codezips |
| software_name | Tourist Management System | Tourist Management System |
| software_version | 1.0 | 1.0 |
| software_file | /admin/change-image.php | /admin/change-image.php |
| software_argument | packageimage | packageimage |
| vulnerability_cwe | CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର) | CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର) |
| vulnerability_risk | 2 | 2 |
| cvss3_vuldb_av | N | N |
| cvss3_vuldb_ac | L | L |
| cvss3_vuldb_pr | H | H |
| cvss3_vuldb_ui | N | N |
| cvss3_vuldb_s | U | U |
| cvss3_vuldb_c | L | L |
| cvss3_vuldb_i | L | L |
| cvss3_vuldb_a | L | L |
| cvss3_vuldb_e | P | P |
| cvss3_vuldb_rc | R | R |
| advisory_url | https://github.com/ppp-src/CVE/issues/13 | https://github.com/ppp-src/CVE/issues/13 |
| exploit_availability | 1 | 1 |
| exploit_publicity | 1 | 1 |
| exploit_url | https://github.com/ppp-src/CVE/issues/13 | https://github.com/ppp-src/CVE/issues/13 |
| source_cve | CVE-2024-9816 | CVE-2024-9816 |
| cna_responsible | VulDB | VulDB |
| cvss2_vuldb_av | N | N |
| cvss2_vuldb_ac | L | L |
| cvss2_vuldb_au | M | M |
| cvss2_vuldb_ci | P | P |
| cvss2_vuldb_ii | P | P |
| cvss2_vuldb_ai | P | P |
| cvss2_vuldb_e | POC | POC |
| cvss2_vuldb_rc | UR | UR |
| cvss4_vuldb_av | N | N |
| cvss4_vuldb_ac | L | L |
| cvss4_vuldb_pr | H | H |
| cvss4_vuldb_ui | N | N |
| cvss4_vuldb_vc | L | L |
| cvss4_vuldb_vi | L | L |
| cvss4_vuldb_va | L | L |
| cvss4_vuldb_e | P | P |
| cvss2_vuldb_rl | ND | ND |
| cvss3_vuldb_rl | X | X |
| cvss4_vuldb_at | N | N |
| cvss4_vuldb_sc | N | N |
| cvss4_vuldb_si | N | N |
| cvss4_vuldb_sa | N | N |
| cvss2_vuldb_basescore | 5.8 | 5.8 |
| cvss2_vuldb_tempscore | 5.0 | 5.0 |
| cvss3_vuldb_basescore | 4.7 | 4.7 |
| cvss3_vuldb_tempscore | 4.3 | 4.3 |
| cvss3_meta_basescore | 4.7 | 4.7 |
| cvss3_meta_tempscore | 4.3 | 4.5 |
| cvss4_vuldb_bscore | 5.1 | 5.1 |
| cvss4_vuldb_btscore | 2.0 | 2.0 |
| advisory_date | 1728511200 (10/10/2024) | 1728511200 (10/10/2024) |
| price_0day | $0-$5k | $0-$5k |
| cve_nvd_summary | A vulnerability was found in Codezips Tourist Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| cvss4_cna_av | N | |
| cvss4_cna_ac | L | |
| cvss4_cna_at | N | |
| cvss4_cna_pr | H | |
| cvss4_cna_ui | N | |
| cvss4_cna_vc | L | |
| cvss4_cna_vi | L | |
| cvss4_cna_va | L | |
| cvss4_cna_sc | N | |
| cvss4_cna_si | N | |
| cvss4_cna_sa | N | |
| cvss3_cna_av | N | |
| cvss3_cna_ac | L | |
| cvss3_cna_pr | H | |
| cvss3_cna_ui | N | |
| cvss3_cna_s | U | |
| cvss3_cna_c | L | |
| cvss3_cna_i | L | |
| cvss3_cna_a | L | |
| cvss3_cna_basescore | 4.7 | |
| cvss2_cna_av | N | |
| cvss2_cna_ac | L | |
| cvss2_cna_au | M | |
| cvss2_cna_ci | P | |
| cvss2_cna_ii | P | |
| cvss2_cna_ai | P | |
| cvss2_cna_basescore | 5.8 | |
| cvss4_cna_bscore | 5.1 |