peter bassill · operator
$ cve CVE-2020-24199 JSON

CVE-2020-24199

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.69% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2020-09-09
Last modified2026-06-17

Affected (1)

VendorProduct
projectworldscar rental project

References

→ the Explorer  ·  watch your stack  ·  NVD