Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.
                
            References
                    | Link | Resource | 
|---|---|
| http://packetstormsecurity.com/files/164625/Online-Student-Admission-System-1.0-SQL-Injection-Shell-Upload.html | Third Party Advisory VDB Entry | 
| https://packetstormsecurity.com/files/164625/Online_Admission_System_CVEs-Gerard-Carbonell.pdf | Third Party Advisory VDB Entry | 
| https://www.sourcecodester.com/php/14874/online-student-admission-system.html | Third Party Advisory | 
| http://packetstormsecurity.com/files/164625/Online-Student-Admission-System-1.0-SQL-Injection-Shell-Upload.html | Third Party Advisory VDB Entry | 
| https://packetstormsecurity.com/files/164625/Online_Admission_System_CVEs-Gerard-Carbonell.pdf | Third Party Advisory VDB Entry | 
| https://www.sourcecodester.com/php/14874/online-student-admission-system.html | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 06:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://packetstormsecurity.com/files/164625/Online-Student-Admission-System-1.0-SQL-Injection-Shell-Upload.html - Third Party Advisory, VDB Entry | |
| References | () https://packetstormsecurity.com/files/164625/Online_Admission_System_CVEs-Gerard-Carbonell.pdf - Third Party Advisory, VDB Entry | |
| References | () https://www.sourcecodester.com/php/14874/online-student-admission-system.html - Third Party Advisory | 
28 Oct 2021, 16:49
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:online_student_admission_system_project:online_student_admission_system:1.0:*:*:*:*:*:*:* | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 6.5
         v3 : 8.8  | 
| CWE | CWE-434 | |
| References | (MISC) https://www.sourcecodester.com/php/14874/online-student-admission-system.html - Third Party Advisory | |
| References | (MISC) http://packetstormsecurity.com/files/164625/Online-Student-Admission-System-1.0-SQL-Injection-Shell-Upload.html - Third Party Advisory, VDB Entry | |
| References | (MISC) https://packetstormsecurity.com/files/164625/Online_Admission_System_CVEs-Gerard-Carbonell.pdf - Third Party Advisory, VDB Entry | 
26 Oct 2021, 13:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2021-10-26 13:15
Updated : 2024-11-21 06:15
NVD link : CVE-2021-37372
Mitre link : CVE-2021-37372
CVE.ORG link : CVE-2021-37372
JSON object : View
Products Affected
                online_student_admission_system_project
- online_student_admission_system
 
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
