Vulnerability Description
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Projectworlds | Car Rental Project | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebAppExploitThird Party Advisory
- https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp/blob/master/CarExploitThird Party Advisory
- https://projectworlds.in/free-projects/php-projects/car-rental-project-in-php-anProduct
- https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebAppExploitThird Party Advisory
- https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp/blob/master/CarExploitThird Party Advisory
- https://projectworlds.in/free-projects/php-projects/car-rental-project-in-php-anProduct
FAQ
What is CVE-2020-24199?
CVE-2020-24199 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
How severe is CVE-2020-24199?
CVE-2020-24199 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-24199?
Check the references section above for vendor advisories and patch information. Affected products include: Projectworlds Car Rental Project.