CVE-2019-13294
CRITICALAROX School-ERP Pro - Unauthenticated Remote Code Execution via import_stud.php and upload_fille.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-13294. PoCs published by AkkuS.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated remote code execution vulnerability in AROX School-ERP Pro by uploading a malicious PHP file via the 'upload_fille.php' endpoint, which lacks session control.
Description
AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthenticated user can execute a command on the system.
Exploits (1)
This Metasploit module exploits an unauthenticated remote code execution vulnerability in AROX School-ERP Pro by uploading a malicious PHP file via the 'upload_fille.php' endpoint, which lacks session control.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H