CVE-2025-60500

QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.
References
Configurations

No configuration.

History

21 Oct 2025, 19:31

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

21 Oct 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-21 17:15

Updated : 2025-10-21 19:31


NVD link : CVE-2025-60500

Mitre link : CVE-2025-60500

CVE.ORG link : CVE-2025-60500


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type