A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads to unrestricted upload.
This vulnerability was named CVE-2024-11214. The attack can be initiated remotely. Furthermore, there is an exploit available.
The initial researcher disclosure contains confusing vulnerability classes.