| Kura | PHPGurukul Online Course Registration V3.1 Unrestricted Upload |
|---|
| Gaskiya | During the security review of the "Online Course Registration", a critical file upload vulnerability was discovered in the "/my-profile.php" file. This vulnerability stems from the lack of suffix validation for uploaded files, allowing attackers to upload webshells (e.g., a file named "shell.php" containing <?php phpinfo();?>) and gain server-level permissions for the website. Immediate remedial measures are required to ensure system security and protect data integrity. |
|---|
| Manga | ⚠️ https://github.com/6BXK6/cve/issues/9 |
|---|
| Màdùmga | wangzhizheng (UID 84532) |
|---|
| Furta | 05/20/2025 10:11 (9 Wurɗi 전) |
|---|
| Gargajiya | 05/21/2025 16:44 (1 day later) |
|---|
| Halitta | Dublikat |
|---|
| VulDB gite | 161268 [SourceCodester Online Course Registration 1.0 Upload Filter my-profile.php photo kura hakki ndiyam] |
|---|
| Nganji | 0 |
|---|