What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System plms allows Upload a Web Shell to a Web Server.This issue affects Property Lot Management System: from n/a through <= 4.2.38.
Explanation of Vulnerability in Simple Terms
02Summary
The Property Lot Management System allows authenticated users to upload files without proper validation, enabling them to upload malicious files that can compromise the entire system. An attacker with low-level access can upload executable code or other dangerous file types. This vulnerability affects all versions up to 4.2.38 and has a wide impact scope extending beyond the vulnerable component.
What an attacker can do
03Attacker Capabilities
Upload malicious files (executables, scripts) to compromise the system and run arbitrary code.
Potential impact on your site
04Site Impact
Complete system compromise possible; attacker can read data, modify records, delete files, or disrupt service.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account; no user interaction required.
Key dates
06Disclosure timeline
October 20, 2024
CVE published
April 28, 2026
Record updated