Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-9659 PoC — School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload

Source
Associated Vulnerability
Title:School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload (CVE-2024-9659)
Description:The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description
CVE-2024-9659: Unrestricted Upload of File with Dangerous Type (CWE-434)
Readme
# CVE-2024-9659: Unrestricted Upload of File with Dangerous Type (CWE-434)

## Overview

The School Management System for WordPress, developed by **dasinfomedia**, is currently facing a critical security vulnerability identified as **CVE-2024-9659**. This vulnerability affects all versions up to and including 91.5.0 of the plugin, and it is categorized as 'CRITICAL' with a CVSS base score of **9.8**.


## Details
+ **CVE ID:** CVE-2024-9659
+ **Published:** 2024-11-23
+ **Impact:** Critical
+ **Exploit Availability:** Not public, only private.
+ **CVSS:** 9.8


## Vulnerability Description

The problem is rooted in the mj_smgt_user_avatar_image_upload() function, which lacks adequate file type validation. This security flaw permits unauthenticated attackers to upload arbitrary files, which will lead to remote code execution on the affected server.


## Affected Versions

Vulnerability affects all versions **up to and including 91.5.0**.


## Usage
```
pip install -r requirements.txt
python exploit.py
```

## Contact
For inquiries, please contact famixcm@thesecure.biz

## Exploit
**[Download Here](https://bit.ly/4eGwPeI)**
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →