Showing 1 vulnerability on this page for Employee Records System

Signals CISA KEV Ransomware Nuclei
SourceCodester vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Employee Records System v1.0 Arbitrary File Upload RCE

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

CWE-434Nov 10, 20251 related artifact
CVSS9.3v4.0EPSS3.19%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX