Employee Records System version 1.0 contains an...
Critical severity
Unreviewed
Published
Nov 11, 2025
to the GitHub Advisory Database
•
Updated Nov 24, 2025
Description
Published by the National Vulnerability Database
Nov 10, 2025
Published to the GitHub Advisory Database
Nov 11, 2025
Last updated
Nov 24, 2025
Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper server-side validation.
References