Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is...
Critical severity
Unreviewed
Published
Oct 25, 2024
to the GitHub Advisory Database
•
Updated Oct 29, 2024
Description
Published by the National Vulnerability Database
Oct 24, 2024
Published to the GitHub Advisory Database
Oct 25, 2024
Last updated
Oct 29, 2024
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The
redirect_if_not_loggedin
function infunctions_security.php
fails to terminate script execution after redirecting unauthenticated users. This flaw allows an unauthenticated attacker to upload arbitrary files, potentially leading to Remote Code Execution.References