← Back to browse · API

CVE-2023-4122

Severity
CRITICAL
CVSS
9.9
EPSS
0.01501
Risk score
40.13
CISA KEV
No
PoC
No
Published
2023-12-07
Modified
2025-05-28
First seen
2026-08-07
Aliases
EUVD-2023-54008, GHSA-46C3-GJP8-Q49W
Products
code-projects:Student Information System 1.0
Sources
euvd EUVD-2023-54008

Description

Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

References