vendor:
Online Student Enrollment System
by:
BKpatron
7.5
CVSS
HIGH
Unauthenticated File Upload
434
CWE
Product Name: Online Student Enrollment System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:campcodes:online_student_enrollment_system:1.0
Platforms Tested: Windows 10
2020
Online Student Enrollment System 1.0 – Unauthenticated Arbitrary File Upload
Online Student Enrollment System version 1.0 suffers from an Unauthenticated File Upload Vulnerability allowing Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously crafted PHP file.
Mitigation:
Implement proper input validation and file upload restrictions. Ensure that only authorized users can access the file upload functionality.