Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Oretnom23
Oretnom23 payroll Management System
CPEs cpe:2.3:a:oretnom23:payroll_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Oretnom23
Oretnom23 payroll Management System

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T16:54:37.899Z

Reserved: 2024-05-09T00:00:00

Link: CVE-2024-34833

cve-icon Vulnrichment

Updated: 2024-08-02T02:59:22.671Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-17T21:15:50.783

Modified: 2025-04-30T16:21:23.247

Link: CVE-2024-34833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.