CVE-2020-24199
CVE-2020-24199 is a critical-severity vulnerability in Projectworlds Car Rental Project with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-434.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v2: 7.5
- EPSS exploit prediction: 4% (89th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-434
- Affected product: Projectworlds Car Rental Project
- Published:
- Last modified:
Description
Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
Frequently asked questions
- What is CVE-2020-24199?
- Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.
- How severe is CVE-2020-24199?
- CVE-2020-24199 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2020-24199 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (89th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-24199?
- CVE-2020-24199 affects Projectworlds Car Rental Project. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-24199?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2020-24199 published?
- CVE-2020-24199 was published on 2020-09-09 and last updated on 2026-06-17.
References
- https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp
- https://github.com/hyd3sec/CarRentalManagement-Unauth-RCE-WebApp/blob/master/CarRental-Unauth-RCE.py
- https://projectworlds.in/free-projects/php-projects/car-rental-project-in-php-and-mysql/
Affected products (1)
- cpe:2.3:a:projectworlds:car_rental_project:1.0:*:*:*:*:*:*:*
More vulnerabilities in Projectworlds Car Rental Project
- CVE-2026-5368 — High (CVSS 7.3): A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of…
- CVE-2025-4457 — High (CVSS 7.3): A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this…
- CVE-2025-4456 — High (CVSS 7.3): A vulnerability classified as critical has been found in Project Worlds Car Rental Project 1.0. Affected is an unknown…
All CVEs affecting Projectworlds Car Rental Project →
Other CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities
- CVE-2026-75949 — Critical (CVSS 10.0): Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 -…
- CVE-2026-74803 — Critical (CVSS 10.0): Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts…
- CVE-2026-66665 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
- CVE-2026-61900 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla…
- CVE-2026-61424 — Critical (CVSS 10.0): Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla…
- CVE-2026-57719 — Critical (CVSS 10.0): Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using…
Browse all CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities →