Record summary

CVE-2023-3187 has a selected CVSS score of 6.3 (medium); EIP currently links 1 catalogued exploit.

Description

A vulnerability, which was classified as critical, has been found in PHPGurukul Teachers Record Management System 1.0. Affected by this issue is some unknown functionality of the file /changeimage.php of the component Profile Picture Handler. The manipulation of the argument newpic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231176.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBTeachers Record Management System 1.0 - File Upload Type ValidationExploitDB exploitby AFFAN AHMEDNot analyzed1 file
ExploitDB

PoC details

References

5