CVE-2021-45835

The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the application through documents.php, which may be used to execute malicious code or lead to code execution.
References
Link Resource
https://github.com/rskoolrash/Online-Admission-System Third Party Advisory
https://github.com/rskoolrash/Online-Admission-System/issues/2 Issue Tracking Third Party Advisory
https://www.exploit-db.com/exploits/50623 Exploit Third Party Advisory VDB Entry
https://github.com/rskoolrash/Online-Admission-System Third Party Advisory
https://github.com/rskoolrash/Online-Admission-System/issues/2 Issue Tracking Third Party Advisory
https://www.exploit-db.com/exploits/50623 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:online_admission_system_project:online_admissions_system:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 06:33

Type Values Removed Values Added
References () https://github.com/rskoolrash/Online-Admission-System - Third Party Advisory () https://github.com/rskoolrash/Online-Admission-System - Third Party Advisory
References () https://github.com/rskoolrash/Online-Admission-System/issues/2 - Issue Tracking, Third Party Advisory () https://github.com/rskoolrash/Online-Admission-System/issues/2 - Issue Tracking, Third Party Advisory
References () https://www.exploit-db.com/exploits/50623 - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/50623 - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2022-03-18 11:15

Updated : 2024-11-21 06:33


NVD link : CVE-2021-45835

Mitre link : CVE-2021-45835

CVE.ORG link : CVE-2021-45835


JSON object : View

Products Affected

online_admission_system_project

  • online_admissions_system
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type