← back
CVE-2024-34833

CVE-2024-34833

CVSS 9.8 CRITICALEPSS 1.9%CWE-434
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 1.9%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
02 May 2024Public PoC
17 Jun 2024Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →