packetstormsecurity.com
http://packetstormsecurity.com/files/172909/Teachers-Record-Management-System-1.0-Validation-Bypass.html CVE-2023-3187
MEDIUM
PHPGurukul Teachers Record Management System Profile Picture changeimage.php unrestricted upload
Record summary
CVE-2023-3187 has a selected CVSS score of 6.3 (medium); EIP currently links 1 catalogued exploit.
Description
A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some unknown functionality of the file /changeimage.php of the component Profile Picture Handler. The manipulation of the argument newpic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231176.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Teachers Record Management SystemBrowse PHPGurukul / Teachers Record Management System | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBTeachers Record Management System 1.0 - File Upload Type ValidationExploitDB exploitby AFFAN AHMEDNot analyzed1 file
References
5github.comexploit
https://github.com/ctflearner/Vulnerability/blob/main/Teacher_Record_Management_System/trms.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-3187 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.231176 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.231176