CVE-2024-48594
HIGHPrison Management System 1.0 - Remote Code Execution via File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48594.
PoCs published by Alexandru Ionut Raducu, including Metasploit module exploits/linux/http/prison_management_rce.
AI-analyzed exploit summary This Metasploit module exploits an authenticated unrestricted file upload vulnerability in Prison Management System 1.0, allowing an attacker to upload a PHP webshell via the avatar upload functionality in the add-admin.php endpoint.
Description
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.
Exploits (1)
This Metasploit module exploits an authenticated unrestricted file upload vulnerability in Prison Management System 1.0, allowing an attacker to upload a PHP webshell via the avatar upload functionality in the add-admin.php endpoint.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H