Title: Personnel Property Equipment System v1.0 by sourcecodester has arbitrary code execution (RCE) Bug_Author: Zhang Qi Vendor: https://www.sourcecodester.com/php/11255/personel-property-equipment-system.html Software Version: v1.0 Built Using: xampp-php8.1 version Affected Account: Jonremus/admin (Super Admin Account) Vulnerability URL: ip/ppes/admin/admin_change_picture.php Loophole Location: arbitrary file upload in Personnel Property Equipment System file (RCE). Directory for Uploaded Files: ppes\admin\uploads Request Package for File Upload Result The uploaded PHP file ( ) was successfully executed, indicating arbitrary code execution vulnerability. PHP Version 8.1.0 is used.