Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
School ERP Pro 1.0 Admin Profile Photo Upload Remote Code Execution Vulnerability
Vulnerability Description
School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server.
CVSS Information
N/A
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
Arox School ERP Pro 代码问题漏洞
Vulnerability Description
Arox School ERP Pro是Arox公司的一个一站式自动化管理平台。 Arox School ERP Pro 1.0版本存在代码问题漏洞,该漏洞源于pre-editstudent.inc.php中的文件验证不当,可能导致经过身份验证的管理员用户上传任意PHP文件作为个人资料照片,从而在服务器上执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A