QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.
References
Link | Resource |
---|---|
https://github.com/H4zaz/CVE-2025-60500 |
Configurations
No configuration.
History
21 Oct 2025, 19:31
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
21 Oct 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-21 17:15
Updated : 2025-10-21 19:31
NVD link : CVE-2025-60500
Mitre link : CVE-2025-60500
CVE.ORG link : CVE-2025-60500
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type