CVE-2024-34833
CRITICALOretnom23 Payroll Management System - Unrestricted File Upload
Title source: ruleDescription
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
Exploits (1)
nomisec
WORKING POC
by ShellUnease · poc
https://github.com/ShellUnease/CVE-2024-34833-payroll-management-system-rce
Scores
CVSS v3
9.8
EPSS
0.4205
EPSS Percentile
97.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
oretnom23/payroll_management_system
1.0
Published
Jun 17, 2024
Tracked Since
Feb 18, 2026