vendor:
Schools Alert Management System
by:
M3@Pandas
7.5
CVSS
HIGH
Arbitrary File Deletion
22
CWE
Product Name: Schools Alert Management System
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2018-12053
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux Mint
2018
Schools Alert Management Script – Arbitrary File Deletion
Attackers can delete any file through parameter 'img' with '../' by exploiting the vulnerability in Schools Alert Management Script.
Mitigation:
Input validation should be used to prevent attackers from deleting arbitrary files.