Simple Employee Records System 1.0 RCE

Published on 16 Jun 2021
Vulnerability

The uploadID.php in the Simple Employee Records System v 1.0 can be used to upload php files to the server. Those files will be uploaded to ‘/uploads/employees_ids/’ without any authentication. With the unrestricted file upload the attacker can gain RCE.

Mitigation / Precaution

  • Apply patches provided by the vendor or upgrade the application to a newer version.
Jijith Rajan
Written by
Cyber Security Engineer

His passion for staying abreast of the latest security threats and trends, coupled with his hands-on experience, allows him to actively contribute to the protection of digital assets. Jijith's dedication and enthusiasm make him a promising talent in the ever-evolving realm of cybersecurity, promising a safer digital future.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo