CVE-2025-60500
HIGHQDocs Smart School Management System 7.1 - Auth Bypass
Title source: llmDescription
QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.
References (1)
Core 1
Core References
Exploit, Mitigation, Third Party Advisory
https://github.com/H4zaz/CVE-2025-60500
Scores
CVSS v3
7.2
EPSS
0.0018
EPSS Percentile
39.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-434
Status
published
Products (1)
qdocs/smart_school
7.1.0
Published
Oct 21, 2025
Tracked Since
Feb 18, 2026