CVE-2024-10161
PHPGurukul Boat Booking System Update Boat Image Page change-image.php unrestricted upload
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.6%KEV nãoPoC —Patch —
Lifecycle
20 Oct 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. This affects an unknown part of the file change-image.php of the component Update Boat Image Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
PHPGurukul · Boat Booking SystemWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →