← Volver a CVEs
CVE-2024-34833
CRITICAL9.8
Descripcion
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado6/17/2024
Ultima modificacion4/30/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
oretnom23:payroll_management_system
Debilidades (CWE)
CWE-434
Referencias
https://github.com/ShellUnease/payroll-management-system-rce(cve@mitre.org)
https://packetstormsecurity.com/files/179106/Payroll-Management-System-1.0-Remote-Code-Execution.html(cve@mitre.org)
https://github.com/ShellUnease/payroll-management-system-rce(af854a3a-2127-422b-91ae-364da2661108)
https://packetstormsecurity.com/files/179106/Payroll-Management-System-1.0-Remote-Code-Execution.html(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.