Student Information System - File Upload
9.9
Critical
Discovered by

Offensive Team, Fluid Attacks
Summary
Full name
Student Information System v1.0 - Insecure File Upload
Code name
State
Public
Release date
Dec 6, 2023
Affected product
Student Information System
Vendor
Kashipara Group
Affected version(s)
Version 1.0
Vulnerability name
Insecure File Upload
Vulnerability type
Remotely exploitable
Yes
CVSS v3.0 vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v3.0 base score
9.9
Exploit available
Yes
CVE ID(s)
Description
Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
Vulnerability
The 'photo' parameter of the my-profile.php resource does not validate the contents, extension and type of the file uploaded as a profile image, leading to an arbitrary file upload which can be abused to obtain Remote Code Execution. The vulnerable code is:
Our security policy
We have reserved the ID CVE-2023-4122 to refer to this issue from now on. Disclosure policy
System Information
Version: Student Information System v1.0
Operating System: Any
Mitigation
There is currently no patch available for this vulnerability.
References
Vendor page https://www.kashipara.com/
Timeline
Vulnerability discovered
Nov 22, 2023
Vendor contacted
Nov 22, 2023
Public disclosure
Dec 6, 2023