CVE-2024-40394 identifies an arbitrary file upload vulnerability in Simple Library Management System Project Using PHP/MySQL v1.0, specifically within the ajax.php component. This critical vulnerability, rated 9.8 CVSS, allows unauthenticated attackers to remotely upload malicious files without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, the high FAUCET Risk Score indicates significant potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:oretnom23:simple_library_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.