A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
History

Wed, 13 Nov 2024 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Surajkumarvishwakarma
Surajkumarvishwakarma real Estate Management System
CPEs cpe:2.3:a:surajkumarvishwakarma:real_estate_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Surajkumarvishwakarma
Surajkumarvishwakarma real Estate Management System

Fri, 08 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Codeastro
Codeastro real Estate Management System
CPEs cpe:2.3:a:codeastro:real_estate_management_system:*:*:*:*:*:*:*:*
Vendors & Products Codeastro
Codeastro real Estate Management System
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Title CodeAstro Real Estate Management System About Us Page aboutadd.php unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-11-08T08:00:08.825Z

Updated: 2024-11-08T14:24:05.711Z

Reserved: 2024-11-07T20:47:08.262Z

Link: CVE-2024-10999

cve-icon Vulnrichment

Updated: 2024-11-08T14:24:00.705Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-08T08:15:14.597

Modified: 2024-11-13T01:05:34.293

Link: CVE-2024-10999

cve-icon Redhat

No data.