CVE-2021-4462
Employee Records System v1.0 Arbitrary File Upload RCE
Record summary
CVE-2021-4462 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 10, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Employee Records SystemBrowse Employee Records System / Employee Records SystemDefault status: unaffected | CVE List | 1.0 | affected |
Employee Records SystemBrowse SourceCodester / Employee Records System | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBSimple Employee Records System 1.0 - File Upload RCE (Unauthenticated)ExploitDB exploitby smlNot analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALEmployee Records System 1.0 - Unauthenticated File Upload RCECVSS 9.8
Employee Records System version 1.0 contains an unrestricted file upload vulnerability in uploadID.php that allows remote unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.
Impact
Unauthenticated attackers can upload arbitrary PHP files via uploadID.php and achieve remote code execution, leading to complete server compromise.
Remediation
Apply security patches or upgrade to a later version of Employee Records System.
Source: ProjectDiscovery