vendor:
Schools Alert Management System
by:
M3@Pandas
7.5
CVSS
HIGH
Arbitrary File Read
22
CWE
Product Name: Schools Alert Management System
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Yes
Related CWE: CVE-2018-12054
CPE: a:phpscriptsmall:schools_alert_management_system
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=12054, https://www.infosecmatter.com/nessus-plugin-library/?id=12205, https://www.infosecmatter.com/nessus-plugin-library/?id=12065, https://www.infosecmatter.com/nessus-plugin-library/?id=15963, https://www.infosecmatter.com/nessus-plugin-library/?id=15970, https://www.infosecmatter.com/nessus-plugin-library/?id=15456, https://www.infosecmatter.com/nessus-plugin-library/?id=12052, https://www.infosecmatter.com/nessus-plugin-library/?id=15572, https://www.infosecmatter.com/nessus-plugin-library/?id=12209, https://www.infosecmatter.com/nessus-plugin-library/?id=12055
Platforms Tested: Linux Mint
2018
Schools Alert Management Script – Arbitrary File Read
The Schools Alert Management Script is vulnerable to an arbitrary file read vulnerability. An attacker can exploit this vulnerability by sending a crafted request to the img.php file with a malicious file path. This will allow the attacker to read any file on the server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of the Schools Alert Management Script.