CVE-2024-4809
Last modified
CVE-2024-4809 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file setting.php. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file setting.php. The manipulation of the argument logo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263929 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nikhil-Bhalerao | Open Source Clinic Management System | 1.0 |
References
- https://github.com/CveSecLook/cve/issues/26Exploit, Third Party Advisory
- https://vuldb.com/?ctiid.263929Permissions Required, VDB Entry
- https://vuldb.com/?id.263929Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.332581Third Party Advisory, VDB Entry
- https://github.com/CveSecLook/cve/issues/26Exploit, Third Party Advisory
- https://vuldb.com/?ctiid.263929Permissions Required, VDB Entry
- https://vuldb.com/?id.263929Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.332581Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4809?
How severe is CVE-2024-4809?
How do I fix CVE-2024-4809?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-48073sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecu…9.8
- CVE-2024-48074An authorized RCE vulnerability exists in the DrayTek Vigor2…8
- CVE-2024-48075A Heap buffer overflow in the server-site handshake implemen…5.3
- CVE-2024-48077NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due …7.5
- CVE-2024-4808A vulnerability, which was classified as critical, was found…8.8
- CVE-2024-48080An issue in aedes v0.51.2 allows attackers to cause a Denial…7.5
- CVE-2024-48091Tally Prime Edit Log v2.1 was discovered to contain a DLL hi…7.8
- CVE-2024-48093Unrestricted File Upload in the Discussions tab in Operately…8
- CVE-2024-4810Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-48107SparkShop <=1.1.7 is vulnerable to server-side request forge…6.5
- CVE-2024-4811In affected versions of Octopus Server under certain conditi…2.2
- CVE-2024-48112A deserialization vulnerability in the component \controller…9.8
Are you affected by CVE-2024-4809?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
