Record summary

CVE-2021-4462 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 10, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List1.0affected
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBSimple Employee Records System 1.0 - File Upload RCE (Unauthenticated)ExploitDB exploitby smlNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALEmployee Records System 1.0 - Unauthenticated File Upload RCECVSS 9.8

Employee Records System version 1.0 contains an unrestricted file upload vulnerability in uploadID.php that allows remote unauthenticated attackers to upload arbitrary PHP files and achieve remote code execution.

Impact

Unauthenticated attackers can upload arbitrary PHP files via uploadID.php and achieve remote code execution, leading to complete server compromise.

Remediation

Apply security patches or upgrade to a later version of Employee Records System.

WeaknessesCWE-434
Authorsjosephttd
Template tagscvecve2021employee-recordsfileuploadrceintrusivevkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: ProjectDiscovery

References

4