A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
History

Tue, 29 Oct 2024 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Janobe
Janobe online Hotel Reservation System
CPEs cpe:2.3:a:janobe:online_hotel_reservation_system:1.0:*:*:*:*:*:*:*
Vendors & Products Janobe
Janobe online Hotel Reservation System

Tue, 29 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester online Hotel Reservation System
CPEs cpe:2.3:a:sourcecodester:online_hotel_reservation_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Hotel Reservation System
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 27 Oct 2024 03:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Title SourceCodester Online Hotel Reservation System controller.php upload unrestricted upload
Weaknesses CWE-434
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-10-27T03:31:05.066Z

Updated: 2024-10-29T13:19:56.078Z

Reserved: 2024-10-26T07:21:42.196Z

Link: CVE-2024-10410

cve-icon Vulnrichment

Updated: 2024-10-29T13:19:46.474Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-27T04:15:02.617

Modified: 2024-10-29T20:41:20.520

Link: CVE-2024-10410

cve-icon Redhat

No data.