PT-2020-12177 · Unknown · School Manage System

Jia-Rong Chen

·

Published

2020-04-15

·

Updated

2020-04-30

·

CVE-2020-10507

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The School Manage System versions prior to 2020
Description The issue is related to an unrestricted file upload vulnerability, which allows attackers to gain access to the hosting machine. This is due to a misconfigured file upload filter that permits the upload of any file format to the system.
Recommendations For versions prior to 2020, consider disabling the file upload feature until a proper fix is applied to prevent unrestricted file uploads. Restrict access to the file upload module to minimize the risk of exploitation. Avoid using the file upload functionality in the affected system until the issue is resolved.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10507

Affected Products

School Manage System