Vulnerability CVE-2024-0192


Published: 2024-01-02

Description:
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file downloadable.php of the component Add Downloadable. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249505 was assigned to this vulnerability.

Type:

CWE-434

(Unrestricted Upload of File with Dangerous Type)

 References:
https://vuldb.com/?id.249505
https://vuldb.com/?ctiid.249505
https://mega.nz/file/2RNnjDTR#nDT4E74juKhdO3eWTv8VjDD2dDcNUzyAk2UR3psM8rM

Copyright 2026, cxsecurity.com

 

Back to Top