
Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental System.
This repository contains details about the vulnerabilities identified in Code-Projects Online Car Rental System project Version 1.0. The vulnerabilities have been assigned CVEs and include comprehensive writeups to assist in understanding and mitigating the issues.
Remote Code Execution (Authenticated) via File Upload
Stored XSS (Authenticated) in edit-vehicle.php
These vulnerabilities have been responsibly disclosed to the project maintainers.