CVE-2021-25200: Malicious File Upload
Published Jul 28, 2021
·Updated
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\studentavatar.php.
Affected Software
1 affected component
Learning Management System Project Learning Management System=1.0
Event History
Jul 28, 2021
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-25200.
2
What is the severity of CVE-2021-25200?
The severity of CVE-2021-25200 is critical.
3
How does CVE-2021-25200 affect SourceCodester Learning Management System?
CVE-2021-25200 allows attackers to execute arbitrary code in SourceCodester Learning Management System v 1.0.
4
How can an attacker exploit CVE-2021-25200?
An attacker can exploit CVE-2021-25200 by uploading a malicious file to the \lms\student_avatar.php file.
5
Is there a fix available for CVE-2021-25200?
Yes, a fix for CVE-2021-25200 is available. Please refer to the reference link for more information.