CVE-2024-1027

MEDIUM

Oretnom23 Facebook News Feed Like - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is an unknown function of the component Post Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-252300.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry
https://vuldb.com/?id.252300
Permissions Required, Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.252300

Scores

CVSS v3 6.3
EPSS 0.0006
EPSS Percentile 17.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
oretnom23/facebook_news_feed_like 1.0
Published Jan 30, 2024
Tracked Since Feb 18, 2026