Campcodes School File Management System Unrestricted File Upload Vulnerability

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in Campcodes School File Management System version 1.0. The issue arises in the file '/save_file.php', where the application fails to properly sanitize or filter uploaded files. This flaw enables the upload of potentially dangerous file types that could be executed within the application's environment, leading to a risk of remote code execution.

Impact

Exploitation of this vulnerability allows for unrestricted file uploads, which can be used to upload malicious files that may be executed on the server, potentially leading to remote code execution.

Reproduction

To reproduce this vulnerability, upload a file through the 'save_file.php' endpoint. The application does not validate or restrict the type of file being uploaded, allowing harmful files to be uploaded successfully. After uploading, the file can be accessed through the application's file management system, demonstrating the successful exploitation of the vulnerability.

Added: Jan 1, 2026, 2:18 PM
Updated: Jan 1, 2026, 2:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
0.0
relevance
1.8
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.