Simple Employee Records System 1.0 contains an arbitrary file upload vulnerability due to client-side validation of file extensions. This can be used to upload executable code to the server to obtain access or perform remote command execution.
id: CVE-2019-20183
info:
name: Simple Employee Records System 1.0 - Unrestricted File Upload
au
...