Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33092 | A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 29 Oct 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Janobe
Janobe online Hotel Reservation System |
|
| CPEs | cpe:2.3:a:janobe:online_hotel_reservation_system:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Janobe
Janobe online Hotel Reservation System |
Tue, 29 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcecodester
Sourcecodester online Hotel Reservation System |
|
| CPEs | cpe:2.3:a:sourcecodester:online_hotel_reservation_system:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sourcecodester
Sourcecodester online Hotel Reservation System |
|
| Metrics |
ssvc
|
Sun, 27 Oct 2024 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. Affected by this vulnerability is the function upload of the file /admin/mod_room/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | SourceCodester Online Hotel Reservation System controller.php upload unrestricted upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-10-29T13:19:56.078Z
Reserved: 2024-10-26T07:21:42.196Z
Link: CVE-2024-10410
Updated: 2024-10-29T13:19:46.474Z
Status : Analyzed
Published: 2024-10-27T04:15:02.617
Modified: 2024-10-29T20:41:20.520
Link: CVE-2024-10410
No data.
OpenCVE Enrichment
No data.
EUVD