Vulnerability Description
An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Code-Projects | Student Enrollment | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/ASR511-OO7/CVE-2023-41505/blob/main/CVE-24Third Party Advisory
- https://github.com/ASR511-OO7/CVE-2023-41505/blob/main/CVE-24Third Party Advisory
FAQ
What is CVE-2023-41505?
CVE-2023-41505 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
How severe is CVE-2023-41505?
CVE-2023-41505 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-41505?
Check the references section above for vendor advisories and patch information. Affected products include: Code-Projects Student Enrollment.