ZeroHour

CVE-2021-46013

PoC
CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
Modified
Description

An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing " " gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.

Vendors
free school management software project
Products
free school management software
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.