Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .jpg extension, changing the Content-Type to image/php, and placing PHP code after the JPEG data. This ultimately allows execution of arbitrary PHP code.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SchoolCMS 安全漏洞
Vulnerability Description
SchoolCMS是一套基于ThinkPHP框架的开源学校教务管理系统。该系统包括学生管理、成绩管理和教师管理等。 SchoolCMS 2.3.1版本中存在安全漏洞。攻击者可借助logo上传功能通过自定义的Content-Type控制上传文件的后缀利用该漏洞执行任意的PHP代码。
CVSS Information
N/A
Vulnerability Type
N/A