CVE-2024-9815
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Summary
CVE-2024-9815 identifies a critical vulnerability in Codezips Tourist Management System version 1.0, specifically affecting the file /admin/create-package.php due to unrestricted file uploads through the packageimage argument. This flaw allows attackers to exploit this functionality remotely, posing a risk of unauthorized access and potential compromise of sensitive data. The vulnerability has been publicly disclosed and can be exploited with low attack complexity and no user interaction required, although it requires high privileges. Organizations using this software should remediate the issue by restricting file uploads and validating file types to prevent exploitation. The vulnerability is categorized under CWE-434 (Unrestricted Upload of File with Dangerous Type) and carries a medium severity score based on its potential impact.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.