CVE-2020-24199

CRITICAL

Project Worlds Car Rental Management System <1.0 - RCE

Title source: llm
STIX 2.1

Description

Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.

Scores

CVSS v3 9.8
EPSS 0.0339
EPSS Percentile 87.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
projectworlds/car_rental_project 1.0
Published Sep 09, 2020
Tracked Since Feb 18, 2026