Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm3m-8f44-m4v9

Опубликовано: 04 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.

EPSS

Процентиль: 64%
0.00463
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
3 месяца назад

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.

EPSS

Процентиль: 64%
0.00463
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434