CVE-2024-31610
Severity
6.3MEDIUM
EPSS
0.2%
top 57.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateApr 26
Description
File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.4
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-r8hh-gm8p-9j5x: File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1↗2024-04-26
CVEList▶
CVE-2024-31610: File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1↗2024-04-25