CVE-2024-57487

MEDIUM

Car Rental System 1.0 File Upload RCE (Authenticated)

Title source: metasploit

Description

In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

Exploits (2)

nomisec WRITEUP
by aaryan-11-x · poc
https://github.com/aaryan-11-x/CVE-2024-57487-and-CVE-2024-57488
metasploit WORKING POC NORMAL
by Aaryan Golatkar · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/carrental_fileupload_rce.rb

Scores

CVSS v3 6.5
EPSS 0.4510
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-94
Status published

Affected Products (1)

code-projects/online_car_rental_system

Timeline

Published Jan 13, 2025
Tracked Since Feb 18, 2026