Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-60500

Опубликовано: 21 окт. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qdocs:smart_school:7.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00079
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
github
4 месяца назад

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.

EPSS

Процентиль: 24%
0.00079
Низкий

7.2 High

CVSS3

Дефекты

CWE-434