PT-2020-12177 · Unknown · School Manage System
Jia-Rong Chen
·
Published
2020-04-15
·
Updated
2020-04-30
·
CVE-2020-10507
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The School Manage System versions prior to 2020
Description
The issue is related to an unrestricted file upload vulnerability, which allows attackers to gain access to the hosting machine. This is due to a misconfigured file upload filter that permits the upload of any file format to the system.
Recommendations
For versions prior to 2020, consider disabling the file upload feature until a proper fix is applied to prevent unrestricted file uploads. Restrict access to the file upload module to minimize the risk of exploitation. Avoid using the file upload functionality in the affected system until the issue is resolved.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
School Manage System