Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rh3g-ww52-5mx2

Опубликовано: 21 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

EPSS

Процентиль: 24%
0.00079
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
4 месяца назад

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

EPSS

Процентиль: 24%
0.00079
Низкий

7.2 High

CVSS3

Дефекты

CWE-434