Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it from /uploads/, an attacker can execute arbitrary PHP code as the web server user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Code-Projects Scholars Tracking System 安全漏洞
Vulnerability Description
Code-Projects Scholars Tracking System是Code-Projects开源的一个学者追踪系统。 code-projects Scholars Tracking System 1.0版本存在安全漏洞,该漏洞源于文件上传功能未验证文件类型和扩展名,可能导致经过身份验证的攻击者上传并执行任意PHP代码,实现远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A