Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-34833


Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.


Published

2024-06-17T21:15:50.783

Last Modified

2025-04-30T16:21:23.247

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oretnom23 payroll_management_system 1.0 Yes

References