fuzzyap1

2 exploits Active since Jan 2022
CVE-2021-46013 EXPLOITDB CRITICAL text WORKING POC
Sourcecodester Free school management software 1.0 - RCE
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.
CVSS 9.8
EIP-2026-107220 EXPLOITDB text WORKING POC
Free School Management Software 1.0 - 'multiple' Stored Cross-Site Scripting (XSS)