Vulnerability Description
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://github.com/moneymanagerex/web-money-manager-ex/commit/f2850b295ee21bc299
- https://github.com/moneymanagerex/web-money-manager-ex/issues/51
- https://github.com/moneymanagerex/web-money-manager-ex/releases/tag/v1.2.3
- https://youtu.be/JaOrlT9G3yo?t=88
FAQ
What is CVE-2024-41617?
CVE-2024-41617 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution ...
How severe is CVE-2024-41617?
CVE-2024-41617 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-41617?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.