ZeroWdd Studentmanager Unrestricted File Upload Vulnerability

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in ZeroWdd Studentmanager version 1.0. This issue arises in the StudentController and TeacherController files, where the addStudent, editStudent, addTeacher, and editTeacher methods fail to properly restrict file extensions and content. As a result, malicious JSP and HTML files can be uploaded. However, uploaded JSP files cannot be accessed until the application is restarted.

Impact

Exploitation of this vulnerability allows for arbitrary file uploads, including potentially malicious JSP files, which could be executed on the server.

Reproduction

To reproduce this vulnerability, upload a JSP or HTML file using the affected methods in the StudentController or TeacherController. After uploading a JSP file, restart the application to access the file. HTML files can be accessed immediately after upload.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.