Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-24317. PoCs published by angelopioamirante.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-24317, targeting the Judging Management System v1.0. The exploit chains an authentication bypass via SQL injection with an unrestricted file upload vulnerability to achieve remote code execution (RCE) via a PHP webshell.
Description
Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.
Exploits (1)
This repository contains a functional exploit for CVE-2023-24317, targeting the Judging Management System v1.0. The exploit chains an authentication bypass via SQL injection with an unrestricted file upload vulnerability to achieve remote code execution (RCE) via a PHP webshell.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N