ZeroHour

CVE-2020-28072

PoC
CVSS 3.1
7.2 high
EPSS
3%p85
Published
()
Modified
Description

A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.

Vendors
alumni management system project
Products
alumni management system
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.