CVE-2018-12054
HIGHNuclei
Schools Alert Management Script - Arbitrary File Read
Record summary
CVE-2018-12054 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBSchools Alert Management Script - Arbitrary File ReadExploitDB exploitby M3@PandasNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHSchools Alert Management Script - Arbitrary File ReadCVSS 7.5
Schools Alert Management Script is susceptible to an arbitrary file read vulnerability via the f parameter in img.php, aka absolute path traversal.
Impact
This vulnerability can lead to unauthorized access to sensitive information stored on the system, potentially exposing personal data of students, staff, and other stakeholders.
Remediation
Apply the latest patch or update provided by the vendor to fix the arbitrary file read vulnerability in the Schools Alert Management Script.
WeaknessesCWE-22
Authorswisnupramoedya
Template tagscvecve2018lfiedbschools_alert_management_script_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:schools_alert_management_script_project:schools_alert_management_script:-:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/44874 https://nvd.nist.gov/vuln/detail/CVE-2018-12054 https://github.com/unh3x/just4cve/issues/4 https://www.exploit-db.com/exploits/44874/ https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3github.com
https://github.com/unh3x/just4cve/issues/4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-12054 44874exploit
https://www.exploit-db.com/exploits/44874