Vulnerability Details CVE-2024-57487
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.325
EPSS Ranking 96.7%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-57487
-
cpe:2.3:a:code-projects:online_car_rental_system:1.0