← Back to browse · API

CVE-2024-34833

Severity
CRITICAL
CVSS
9.8
EPSS
0.01923
Risk score
39.87
CISA KEV
No
PoC
No
Published
2024-06-17
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2024-35096, GHSA-2VPQ-2H36-8FQ9
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-35096

Description

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.

References