Home

Description

An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.

PUBLISHED Reserved 2024-11-20 | Published 2025-04-26 | Updated 2025-12-12 | Assigner mitre




MEDIUM: 6.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-24 Path Traversal: '../filedir'

Product status

Default status
unknown

EagleR-1.0.118 (custom)
affected

References

github.com/...ability-Research-CVEs/tree/main/CVE-2024-53636 exploit

github.com/...ability-Research-CVEs/tree/main/CVE-2024-53636

github.com/...per/cve-research/tree/main/CVEs/CVE-2024-53636

cve.org (CVE-2024-53636)

nvd.nist.gov (CVE-2024-53636)

Download JSON