Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unknown
EagleR-1.0.118 (custom)
affected
Description
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackers to execute arbitrary code via ../ in the filePath parameter.
Problem types
CWE-24 Path Traversal: '../filedir'
Product status
EagleR-1.0.118 (custom)
References
github.com/...ability-Research-CVEs/tree/main/CVE-2024-53636
github.com/...ability-Research-CVEs/tree/main/CVE-2024-53636
github.com/...per/cve-research/tree/main/CVEs/CVE-2024-53636