Description


A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

References


https://github.com/LaneyYu/cve/issues/7

ExploitIssue TrackingThird Party Advisory

https://vuldb.com/?ctiid.339324

Permissions RequiredVDB Entry

https://vuldb.com/?id.339324

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.728102

Third Party AdvisoryVDB Entry

Weaknesses



CWE-284CWE-434


CWE-434

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

6.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2026-01-01T14:16:16.330Z

2 weeks ago

Last modified

2026-01-06T19:19:17.590Z

1 week ago