github.comexploit
https://github.com/llixixi/Engineers-Online-Portal-System/blob/main/Engineers%20Online%20Portal%20System%20has%20a%20file%20upload%20(RCE)%20vulnerability.pdf CVE-2023-5277
MEDIUM
SourceCodester Engineers Online Portal student_avatar.php unrestricted upload
Record summary
CVE-2023-5277 has a selected CVSS score of 6.3 (medium).
Description
A vulnerability, which was classified as critical, has been found in SourceCodester Engineers Online Portal 1.0. This issue affects some unknown processing of the file student_avatar.php. The manipulation of the argument change leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240905 was assigned to this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Engineers Online PortalBrowse SourceCodester / Engineers Online Portal | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-5277 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.240905 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.240905