Description
School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
Besim ALTINOK, İsmail BOZKURT
References
www.exploit-db.com/exploits/48392 (ExploitDB-48392)
web.archive.org/web/20200129123503/http://arox.in/ (Archived Vendor Homepage)
web.archive.org/...ceforge.net/projects/school-erp-ultimate/ (Archived SourceForge Product Page)
www.vulncheck.com/...oad-remote-code-execution-vulnerability (VulnCheck Advisory: School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability)