PT-2021-16792 · Unknown · Baby Care System

Published

2021-02-17

·

Updated

2025-11-18

·

CVE-2021-25780

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Baby Care System version 1.0
Description An arbitrary file upload issue has been identified in posts.php. This could be exploited by a remote attacker to upload content to the server, including PHP files, potentially resulting in command execution and obtaining a shell.
Recommendations For Baby Care System version 1.0, consider restricting access to the posts.php file until a patch is available. As a temporary workaround, disabling the file upload functionality in posts.php could help minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25780

Affected Products

Baby Care System