ZeroHour

CVE-2021-37372

CVSS 3.1
8.8 high
EPSS
3%p88
Published
()
Modified
Description

Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

Vendors
online student admission system project
Products
online student admission system
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.