CVE-2021-46013
CRITICALSourcecodester Free school management software 1.0 - RCE
Title source: llmDescription
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets uploaded it is saved into /uploads/exam_question/ directory, and is accessible by all users.
Exploits (1)
Scores
CVSS v3
9.8
EPSS
0.0240
EPSS Percentile
85.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
free_school_management_software_project/free_school_management_software
1.0
Published
Jan 18, 2022
Tracked Since
Feb 18, 2026